cybercentry-web-application-verification

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core behavior matches its stated purpose, but its footprint is high risk. It gives an AI agent offensive web-scanning capability, routes target data to an external paid service, and explicitly encourages forwarding authenticated session cookies to that service. The ACP CLI install path adds moderate supply-chain trust concerns, and the external data retention model is expansive. Not confirmed malware, but risky and disproportionate for unsupervised agent use.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:25 AM
Package URL
pkg:socket/skills-sh/Cybercentry%2Fcybercentry-agent-skills%2Fcybercentry-web-application-verification%2F@30113c1eb9f73a00813bb1d71ab5e83f83af225c