web-app-penetration-testing

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned as a pentesting workflow, but it is inherently high risk because it equips an AI agent to run active exploits against live systems and forward credentials into external tooling. The Strix install path appears same-org and documented, so this is not strong malware evidence, but the offensive capability, credential handling, and optional cloud data flow make it a high-risk vulnerable skill.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Sep 2, 2026, 02:07 AM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Fweb-app-penetration-testing%2F@536a03685fd56fd81e795632627a924cff38351ef0abbb2522212dc07f13fd51
Security Audit — socket — web-app-penetration-testing