cairn-ai-pentest

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH RISK. The skill is purpose-aligned for offensive security, but that purpose itself grants an AI agent autonomous exploit/scanning capability, processes untrusted target content, and includes an unsafe shell=True pattern. The install source is only moderately trustworthy based on the provided evidence, with no strong release provenance. No clear credential theft or exfiltration is shown, so this is not confirmed malware, but it is a high-risk offensive automation skill.

Confidence: 90%Severity: 88%
Audit Metadata
Analyzed At
Apr 23, 2026, 04:36 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fcairn-ai-pentest%2F@b94c88327739da6db818d00f0ff29eaab30e1d09