Security Scanning Tools
Audited by Socket on Feb 19, 2026
1 alert found:
Malware[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] This skill is a comprehensive, dual-use security scanning guide that lists many legitimate tools and commands for discovery, vulnerability assessment, web/wireless testing, malware scanning, cloud audit, and compliance. It does not contain obfuscated code, embedded backdoors, hardcoded secrets, or third-party exfiltration endpoints. However, it includes potentially disruptive offensive actions (deauthentication, Metasploit exploitation) and high-impact scanning examples (masscan 0.0.0.0/0, high packet rates) which can be misused if executed without authorization. Overall the content is consistent with its stated purpose, but users must obtain authorization, exercise caution with elevated privileges and credential handling, and avoid using high-rate or wide-scoped scans against unauthorized targets. LLM verification: This SKILL.md is a legitimate, capability-aligned guide for authorized security scanning and penetration-testing activities. It does not contain obfuscated malware or explicit data-exfiltration code. However, it includes several supply-chain and operational risks: unpinned pip installs (prowler, scoutsuite), broad instructions requiring root and network access, and example commands that encourage large-scale or high-speed scanning (masscan 0.0.0.0/0, high --rate values) which are disproportionat