security-research

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK vulnerable skill, not confirmed malware. Its footprint matches its stated purpose, but that purpose is to give an AI agent offensive security-audit and PoC capabilities over untrusted codebases, which is inherently high risk; install trust is comparatively moderate because no new third-party binary is introduced by the skill itself.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Aug 1, 2026, 02:36 PM
Package URL
pkg:socket/skills-sh/Yeachan-Heo%2Foh-my-opencode-lite%2Fsecurity-research%2F@87f9062590bca360fd4316d756032c8c52b276a2c249e634982a2c2b4c45a18c
Security Audit — socket — security-research