vigolium-scanner
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a vulnerability-scanner operator guide, but it enables high-risk offensive actions, autonomous agent-driven scanning, execution of custom JS extensions, and processing of untrusted external content. The largest concern is that the core Vigolium CLI and its agent backend data flows are not independently verifiable from the provided evidence, leaving substantial install-trust and data-routing uncertainty.
Confidence: 88%Severity: 89%
Audit Metadata