web-app-penetration-testing
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned as a pentesting workflow, but it is inherently high risk because it equips an AI agent to run active exploits against live systems and forward credentials into external tooling. The Strix install path appears same-org and documented, so this is not strong malware evidence, but the offensive capability, credential handling, and optional cloud data flow make it a high-risk vulnerable skill.
Confidence: 89%Severity: 84%
Audit Metadata