performing-authenticated-vulnerability-scan

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

High-risk but not confirmed malware. The skill is internally aligned with authenticated vulnerability scanning, but it grants an AI agent offensive security capability, uses highly privileged credentials, and weakens TLS verification with curl -k; these make it dangerous to deploy even though it does not show clear credential theft or third-party exfiltration.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Apr 10, 2026, 06:29 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-authenticated-vulnerability-scan%2F@3b6504d84b2e6991a056e767aa79b590f5e29ac0