responder-poison

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能与其声明用途一致,但声明用途本身就是网络投毒、凭据捕获、认证中继和远程利用。不存在明显伪装型恶意分发迹象,但它为 AI 代理提供了高风险 offensive security 能力,应判定为高风险且可疑,而非正常通用技能。

Confidence: 96%Severity: 94%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fresponder-poison%2F@9d0fd34e242c7a7d71889584a411a3d3fdd86c63