web-app-penetration-testing

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned as a pentesting workflow, but it is inherently high risk because it equips an AI agent to run active exploits against live systems and forward credentials into external tooling. The Strix install path appears same-org and documented, so this is not strong malware evidence, but the offensive capability, credential handling, and optional cloud data flow make it a high-risk vulnerable skill.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Aug 20, 2026, 11:39 PM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Fweb-app-penetration-testing%2F@7c0fd53d0648ba20052532bc823f40d7659f4e65eb800e3ec7d60e9b27460d8d
Security Audit — socket — web-app-penetration-testing