hack
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive security capability. There is no clear credential-harvesting or covert exfiltration in the skill text, and the static prompt-injection findings are weak, but the overall capability set is high risk by design for an agent environment. Distribution evidence adds moderate supply-chain concern without proving malicious intent.
Confidence: 87%Severity: 76%
Audit Metadata