llm-security

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an LLM red-team skill, but its actual footprint is inherently high risk because it equips the agent with offensive security techniques, prompt extraction behavior, and indirect prompt-injection workflows. Install trust is mostly acceptable via official registries, though unpinned packages and ambiguous GitHub tooling raise moderate supply-chain concern.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
Aug 12, 2026, 10:25 PM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fllm-security%2F@7d424989f3742cc264cf1cd72eeee3c966a5562b5fd55ab3a5861c3e9e81b3b7
Security Audit — socket — llm-security