ghost-validate

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally aligned with security-finding validation, but it grants an AI agent offensive testing behavior against live applications and routes that capability through a separate proxy skill/tool chain. No direct malware or credential theft is evident, yet the transitive trust and exploit-testing scope make this a high-security-risk skill.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/ghostsecurity%2Fskills%2Fghost-validate%2F@c54ebf20575f1f57fa15d5b88199a88e671db8872e7539cc00bbde8b0ee0d76f
Security Audit — socket — ghost-validate