Security Scanning Tools

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] The document is a comprehensive, legitimate guide for authorized security scanning and assessment using well-known tools; it does not contain obfuscated code, hard-coded secrets, or hidden exfiltration. However, it includes explicit instructions for potentially disruptive and illegal activities (large-scale scanning, deauthentication, cracking, exploitation), which present a significant misuse risk if executed without proper authorization and controls. Treat the guide as high-privilege operational content: restrict access, require written authorization, and implement procedural safeguards before executing any examples in production or against external networks. LLM verification: This SKILL.md is a legitimate, capability-aligned guide for authorized security scanning and penetration-testing activities. It does not contain obfuscated malware or explicit data-exfiltration code. However, it includes several supply-chain and operational risks: unpinned pip installs (prowler, scoutsuite), broad instructions requiring root and network access, and example commands that encourage large-scale or high-speed scanning (masscan 0.0.0.0/0, high --rate values) which are disproportionat

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 17, 2026, 03:17 AM
Package URL
pkg:socket/skills-sh/zebbern%2Fclaude-code-guide%2Fsecurity-scanning-tools%2F@599e2cf2a3a2076de58f729ce76ca2e53fcad8af