performing-api-inventory-and-discovery

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for API security assessment, but it equips an AI agent with high-risk offensive reconnaissance abilities, including active scanning and cloud inventory enumeration. No clear malware or credential-harvesting behavior is shown, but disabled TLS verification and autonomous network probing make the security risk high.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
Mar 15, 2026, 09:42 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-api-inventory-and-discovery%2F@f789b2a2a55e44a39de5de8bb6115328c577e697