vigolium-scanner

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a vulnerability-scanner operator guide, but it enables high-risk offensive actions, autonomous agent-driven scanning, execution of custom JS extensions, and processing of untrusted external content. The largest concern is that the core Vigolium CLI and its agent backend data flows are not independently verifiable from the provided evidence, leaving substantial install-trust and data-routing uncertainty.

Confidence: 88%Severity: 89%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:45 AM
Package URL
pkg:socket/skills-sh/vigolium%2Fskills%2Fvigolium-scanner%2F@f39c33433ab79e424a4fac59b0e6dd7d76392b78