social-engineering

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches its capabilities, but those capabilities are inherently offensive and enable AI-driven phishing, impersonation, credential harvesting, and physical social-engineering activity. There are no external install or credential-forwarding indicators in the provided text, so this is not confirmed malware; however, as an AI agent skill it is high-risk because it equips the agent to conduct real-world security attacks against people without defined guardrails.

Confidence: 93%Severity: 84%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:18 AM
Package URL
pkg:socket/skills-sh/transilienceai%2Fcommunitytools%2Fsocial-engineering%2F@f391082d146b439d942b581841b0fe08d33bf390