penetration-testing-with-strix

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, and the installer appears to be official same-org infrastructure rather than a disguised credential stealer. However, this is a high-risk AI agent skill because its intended function is autonomous penetration testing and exploitation against live targets, with optional source uploads to Strix cloud and writable local sandbox access; it should be treated as dangerous offensive capability, though not confirmed malware.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Sep 18, 2026, 12:14 AM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Fpenetration-testing-with-strix%2F@85047c026424d6822360c8aefe5b827819e4a27bc3bcab621908d541165bb129
Security Audit — socket — penetration-testing-with-strix