aig-scanner

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-consistent and appears tied to a legitimate Tencent A.I.G project, not an obvious credential-stealing lure. However, it is still a high-risk security-scanning skill: it enables offensive-capable scans, targets private/local services, and forwards model tokens and agent configs to a configured AIG server. This is better classified as a legitimate but high-risk security tool rather than malware.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 16, 2026, 10:01 AM
Package URL
pkg:socket/skills-sh/Tencent%2FAI-Infra-Guard%2Faig-scanner%2F@1a3ab076d4ceb97dcc4ad949e55170cfab968222