building-threat-actor-profile-from-osint
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is purpose-consistent and uses mostly official APIs and standard packages, so it does not look malicious. However, it equips an AI agent with real reconnaissance/threat-intelligence capability, runs a local security scanning tool, and processes untrusted external content with write/exec access, making it a moderate-to-high security-risk cybersecurity skill rather than a benign documentation-only guide.
Confidence: 84%Severity: 68%
Audit Metadata