web3-methodology-research

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Web3 audit methodology guide and shows no clear credential theft or exfiltration, but it gives an AI agent offensive security capabilities and pairs them with executable installs, repo cloning, and third-party PoC execution. Official-source trust is mostly acceptable, yet the unpinned install chain and exploit-oriented scope make overall risk high even without evidence of malware.

Confidence: 91%Severity: 81%
Audit Metadata
Analyzed At
Mar 17, 2026, 04:29 PM
Package URL
pkg:socket/skills-sh/shuvonsec%2Fweb3-bug-bounty-hunting-ai-skills%2Fweb3-methodology-research%2F@098de7d03948f733244509cccd3c49fc9b3a87ff