web-application-verification

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior matches its stated purpose, but that purpose is inherently high risk because it gives an AI agent offensive web security scanning capability and routes work through a third-party CLI/service from a different org than the publisher. No direct credential theft is shown, but the install provenance and autonomous remote scanning make this a high-risk security skill.

Confidence: 89%Severity: 83%
Audit Metadata
Analyzed At
Apr 7, 2026, 04:39 PM
Package URL
pkg:socket/skills-sh/cybercentry%2Fcybercentry-agent-skills%2Fweb-application-verification%2F@c7e65369867f1ef4436d115ede50e43a385ff508