whatweb

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the install paths are mostly coherent with the stated purpose, but this skill’s actual purpose is to give an AI agent offensive web reconnaissance capability. That alone makes it high risk, and the third-party Docker image plus metadata mismatch add trust concerns. No strong evidence of credential theft or covert exfiltration was found.

Confidence: 91%Severity: 81%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:20 PM
Package URL
pkg:socket/skills-sh/TerminalSkills%2Fskills%2Fwhatweb%2F@a2cb056ea3a21a5340f5c744c0db8629b1d0e13d