security-auditor

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally coherent as a security-auditor skill, but it materially includes offensive-security capabilities such as penetration testing, red teaming, and social engineering. There is no evidence of malicious install paths, exfiltration, or credential harvesting in the provided content; the risk comes from empowering an AI agent to perform or guide high-impact security testing.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 14, 2026, 07:12 PM
Package URL
pkg:socket/skills-sh/xfstudio%2Fskills%2Fsecurity-auditor%2F@6535515c51826fb073159350e502c402af59fc47