sast-ssti

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities are internally consistent for a local SSTI-analysis skill, with no supply-chain, credential, or exfiltration concerns. The main risk is that it gives an AI agent structured offensive security scanning capability, including exploit-oriented reasoning and payload generation, so it is best classified as high-risk security tooling rather than malware.

Confidence: 92%Severity: 74%
Audit Metadata
Analyzed At
Apr 8, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/utkusen%2Fsast-skills%2Fsast-ssti%2F@1696ed114fc672067b29b1cfb6de7cf3e4140572