cto

Warn

Audited by Socket on May 5, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/payload/methods/browser-testing-with-devtools.md

SUSPICIOUS: The stated purpose is coherent and the skill includes strong security boundaries, but the installation reference is inconsistent with the official Chrome DevTools MCP publisher/package naming and is unpinned. This looks more like a supply-chain trust problem than malicious intent; browser-content prompt-injection risk is present but acknowledged and mitigated in the instructions.

Confidence: 90%Severity: 56%
AnomalyLOW
references/payload/security/sast-fileupload.md

SUSPICIOUS: the skill is internally consistent and does not show credential theft, exfiltration, or installer abuse, but it materially expands an AI agent’s offensive security capability by directing autonomous vulnerability discovery across a codebase. Risk comes from enabling security scan behavior and processing untrusted code with subagents, not from malware-like behavior.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
May 5, 2026, 02:02 PM
Package URL
pkg:socket/skills-sh/yzfly%2FCTO-Skills%2Fcto%2F@d23eb662a25e97f407b8bb971d200559a3462482