crlfuzz
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: internally coherent as a CRLF injection scanning skill, with mostly legitimate install sources and no obvious credential theft or hidden exfiltration. However, it equips the agent with offensive web fuzzing capability against external targets, which is high risk for an AI agent; supply-chain risk is moderate due to unpinned Go install from a personal GitHub publisher.
Confidence: 95%Severity: 81%
Audit Metadata