security-drill

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are internally consistent for a red-team drill, but it is an offensive-security skill for AI agents and the published contents do not include the referenced execution script, so the implementation and containment claims cannot be verified. No clear credential harvesting or external exfiltration is shown, but the combination of adversarial testing purpose, scheduled execution, and missing core code makes this a high security-risk skill rather than confirmed malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 18, 2026, 01:13 AM
Package URL
pkg:socket/skills-sh/wulaosiji%2Fskills%2Fsecurity-drill%2F@8b4c3ebd224aa60b673ade6f175eff3d87c744ca