web3-ai-tools

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is an AI-enabled offensive security toolkit. It enables autonomous pentesting, exploit generation, system prompt extraction, credential attacks, and transitive installation of third-party security skills; combined with mixed-provenance installs and external-content ingestion, this makes it high risk even without clear evidence of credential theft or covert exfiltration.

Confidence: 93%Severity: 89%
Audit Metadata
Analyzed At
Apr 24, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/shuvonsec%2Fweb3-bug-bounty-hunting-ai-skills%2Fweb3-ai-tools%2F@abebfbe7eb3bdb649bd13ba5fdd0c813f7ce2dc6