crlfuzz

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: internally coherent as a CRLF injection scanning skill, with mostly legitimate install sources and no obvious credential theft or hidden exfiltration. However, it equips the agent with offensive web fuzzing capability against external targets, which is high risk for an AI agent; supply-chain risk is moderate due to unpinned Go install from a personal GitHub publisher.

Confidence: 95%Severity: 81%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fcrlfuzz%2F@d9f15b11dce9f5152da53a865c7556524123fb76f9ff653644dfc75703ec96c0
Security Audit — socket — crlfuzz