web3-audit

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a Web3 audit playbook, but it gives an AI agent offensive security capabilities for exploit discovery and PoC development against real DeFi targets. No clear credential theft, covert exfiltration, or malicious installer behavior is present, so this is high-risk enablement rather than confirmed malware.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fweb3-audit%2F@345eb36ce96c4ca9c1bf0627f9a7d5522722e71f94fe0262837bde4bb222a03a
Security Audit — socket — web3-audit