amass

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能与其声明用途基本一致,未见明显伪装、隐蔽外传或不可信安装链;但它本质上是给 AI 代理提供进攻性侦察能力,并可能读取本地 API 密钥后对外查询。综合看更像高风险安全工具而非恶意窃密技能。

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Apr 8, 2026, 04:47 PM
Package URL
pkg:socket/skills-sh/killvxk%2Fmalskills-zh%2Famass%2F@b2e227eefa79c919bc48dab9dc61cd1d5a83bce7