Security

Fail

Audited by Socket on Mar 23, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose, but that purpose is to equip the agent for offensive security workflows. This router does not itself show credential theft, exfiltration, or malicious installs, yet it meaningfully increases operational risk by directing the agent into recon, pentest, and jailbreak-testing subskills whose contents are not provided.

Confidence: 85%Severity: 74%
MalwareHIGH
PromptInjection/SKILL.md

This skill is not overt malware, but it is a high-risk offensive-security skill for AI agents. Its stated purpose matches its capabilities, yet those capabilities include prompt extraction, jailbreak testing, recon, indirect injection, and multi-stage attacks against external systems. The mandatory localhost curl call adds a small trust concern because the receiving service is unspecified. Overall classification: suspicious/high-risk security tooling rather than benign automation.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Mar 23, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/danielmiessler%2FPersonal_AI_Infrastructure%2Fsecurity%2F@2df9da7ce9f47ac4ee69fcafffac41d4f5f69319