testing-handbook

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a security testing handbook, but it materially expands an AI agent into offensive security activity and includes a notable supply-chain hazard by cloning and executing a Python script from a personal GitHub repo, plus a transitive dependency on another skill. Not confirmed malware, but high operational risk for agent use.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Aug 19, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/woohyun212%2Fsecurity-skill%2Ftesting-handbook%2F@b660948fe16739d9263c82aa0dfa9808de6017f57365fc8335864f3f32913660
Security Audit — socket — testing-handbook