java-route-tracer

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core static-analysis and decompilation behavior broadly matches the stated purpose, but the skill is an offensive security auditing tool and its documented installer path downloads and executes CFR from a non-official proxy without verification. No credential theft or exfiltration is evident, so this is not confirmed malware, but the supply-chain and exploit-tool risks are materially elevated.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
May 1, 2026, 04:43 AM
Package URL
pkg:socket/skills-sh/RuoJi6%2Fjava-audit-skills%2Fjava-route-tracer%2F@1f80a8645f17c795d67aceb0b2ddde419a51d931