performing-purple-team-exercise
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a purple-team guide, but it grants an AI agent offensive security capabilities and real-world command execution against endpoints. The remote installer is same-org and documented, so supply-chain risk is moderate rather than malicious, but the exploit-oriented purpose makes the overall skill high risk.
Confidence: 92%Severity: 86%
Audit Metadata