performing-api-inventory-and-discovery

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent for API discovery, but it equips an AI agent with offensive security scanning capabilities against live infrastructure and includes disabled TLS verification. There is no clear credential theft or exfiltration logic, so this is not confirmed malware, but it is a high-risk cybersecurity skill.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:32 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-api-inventory-and-discovery%2F@360854b092aa90c7eee995748e24a103cf78b130