web-vuln-scan

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an offensive web security methodology, but that coherence is exactly the risk. It equips an AI agent to conduct active vulnerability scanning, default-credential attacks, sensitive-file discovery, and exploit-chain planning against live web targets. No strong malware or supply-chain evidence appears in the shown text, but the capability itself is a high-risk offensive security function for an autonomous agent.

Confidence: 91%Severity: 89%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:00 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fweb-vuln-scan%2F@912a43fc3417a6ce626b5cf627a20759cc1bd538