web-security-testing

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK workflow. The content is coherent with a pentesting purpose, but that purpose itself grants an AI agent offensive security capabilities and delegates to unspecified external skills without provenance or authorization guardrails. No direct malware or exfiltration is shown in this file, but the transitive trust and autonomous attack guidance make it unsafe to classify as benign.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
Apr 11, 2026, 12:44 AM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fweb-security-testing%2F@b59bd396372d7179a5a8c75c26a44347c5cc40e4