vulnerability-scanning

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill is internally coherent as a vulnerability-scanning guide, but it grants an AI agent high-risk offensive security capability and includes a TLS-verification bypass in authenticated API code. Install sources appear mostly official and there is no clear credential exfiltration or malware behavior, so this is high-risk security tooling rather than confirmed malicious content.

Confidence: 91%Severity: 81%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:23 PM
Package URL
pkg:socket/skills-sh/bagelhole%2Fdevops-security-agent-skills%2Fvulnerability-scanning%2F@47ccf76f34c5814c1a2c301c3b881452d6164de6