patt-fetcher

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent but its stated purpose is to supply offensive exploitation payloads, including persistence and evasion content, to an AI agent. Install trust is acceptable because it fetches from an official GitHub raw domain and does not execute downloads, but the use of mutable remote content and prompt enrichment from untrusted exploit material keeps risk high.

Confidence: 94%Severity: 86%
Audit Metadata
Analyzed At
Apr 20, 2026, 11:12 PM
Package URL
pkg:socket/skills-sh/transilienceai%2Fcommunitytools%2Fpatt-fetcher%2F@1a463b88921e19e826c5b7973dda09231b05d6a6