metatron-pentest-assistant

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities are largely consistent with its stated pentesting purpose, but that purpose is itself an offensive-security workflow for an AI agent: installing scanners, executing recon against targets, searching exploit information, and feeding results into an LLM. Supply-chain trust is mixed due to a publisher/repo mismatch, curl|sh install, and a third-party model pull. No clear credential theft or covert exfiltration is shown, so this is not confirmed malware, but it is a high-risk security skill that should not be treated as benign.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Apr 7, 2026, 05:21 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fmetatron-pentest-assistant%2F@937e5adc43ee4835f3ad42e638885e20de744ff4