ai-pentesting

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its stated purpose is autonomous offensive security. The main risks are high-impact exploitation capability, CI automation, unpinned runtime installation of Shannon, and forwarding LLM credentials into external code. This looks more like a high-risk pentesting/exploitation skill than malware, but it should be treated as dangerous.

Confidence: 94%Severity: 88%
Audit Metadata
Analyzed At
Apr 20, 2026, 07:04 AM
Package URL
pkg:socket/skills-sh/TerminalSkills%2Fskills%2Fai-pentesting%2F@1c5237469a5837f2004bd96b7667b6611947d484