web3-start-here

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a web3 security-hunting knowledge base, but its actual purpose is to equip an AI agent with offensive security capabilities, including PoC development and MCP-based live scanning. No direct credential theft, exfiltration, or deceptive data flow is visible in this excerpt, so this is not confirmed malware; risk is driven by the offensive-security use case and the implied execution surface of later MCP tooling.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 17, 2026, 04:28 PM
Package URL
pkg:socket/skills-sh/shuvonsec%2Fweb3-bug-bounty-hunting-ai-skills%2Fweb3-start-here%2F@35d9b5c73fc48f768580575471b0301e67b6bc0c