testing-handbook
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent as a security testing handbook, but it materially expands an AI agent into offensive security activity and includes a notable supply-chain hazard by cloning and executing a Python script from a personal GitHub repo, plus a transitive dependency on another skill. Not confirmed malware, but high operational risk for agent use.
Confidence: 90%Severity: 76%
Audit Metadata