performing-agentless-vulnerability-scanning

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose of agentless vulnerability scanning, and most dependencies/data flows are coherent and official. However, it gives an AI agent high-risk security scanning capabilities and includes disabled trust checks for WinRM TLS and SSH host key validation, creating meaningful security risk even without clear evidence of malware or credential exfiltration.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Mar 15, 2026, 10:51 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-agentless-vulnerability-scanning%2F@65d79e05b46667683bd4690488cfd79759cbcd10