tls-scan-testssl
Audited by Socket on Feb 14, 2026
1 alert found:
Malware[Skill Scanner] URL pointing to executable file detected All findings: [CRITICAL] command_injection: URL pointing to executable file detected (CI010) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] BENIGN overall. The skill fragment describes a legitimate TLS/SSL assessment workflow using testssl.sh with standard input, processing, and output steps. Data flows are limited to TLS scan results, with no evident credential handling or data exfiltration in the described scope. LLM verification: Benign alignment with comprehensive TLS/SSL analysis using testssl.sh. Main concerns center on external tool trust and handling of scan results; address supply-chain risks via source verification and version pinning. No malware indicators detected within the fragment; provide mitigations to strengthen secure usage in automated pipelines.