security-review

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is itself high risk: it equips an AI agent to conduct active penetration testing against live applications. Install trust is mostly benign, but the offensive-security scope, autonomous attack probes, and interaction with untrusted runtime content make this a high-risk skill.

Confidence: 93%Severity: 86%
Audit Metadata
Analyzed At
Apr 19, 2026, 04:33 PM
Package URL
pkg:socket/skills-sh/ShiplightAI%2Fclaude-code-plugin%2Fsecurity-review%2F@05a16052804304a4e8f424e5a12bf77302418b56