web-exploit-technique

Fail

Audited by Socket on Sep 5, 2026

7 alerts found:

Securityx2Malwarex4Anomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an offensive security/exploitation guide, but its footprint is intentionally high risk: it equips an AI agent to perform exploitation, exfiltration, reverse shells, and auth bypass, and may forward tokens to third-party tools. This is not confirmed malware or covert credential theft by the skill itself, but it is a high-risk offensive capability unsuitable outside tightly authorized security testing.

Confidence: 93%Severity: 91%
MalwareHIGH
references/xss-and-client.md

This fragment is an attacker-oriented exploitation/weaponization playbook that automates a headless browser to load attacker-controlled content with host-resolution spoofing, then guides DOM XSS and CSP/script allowlist bypass techniques, postMessage abuse, and stored-XSS payload injection—explicitly including cookie exfiltration patterns. If present in an npm dependency or package artifact, it would represent a major supply-chain security concern. Overall risk is very high based on the offensive intent and inclusion of secret-stealing payloads, though attribution to a specific package behavior cannot be fully confirmed from the snippet alone.

Confidence: 82%Severity: 95%
AnomalyLOW
references/deserialization.md

The provided fragment is an offensive exploitation playbook focused on achieving RCE via unsafe deserialization and JNDI-based techniques across multiple ecosystems. It contains highly actionable, weaponized guidance (including specific tooling commands and payload construction strategies) but does not include actual dependency implementation code to validate runtime behavior, network/file activity, or embedded malware. From a supply-chain security standpoint, inclusion of this content is a serious red flag for malicious usefulness; direct malware presence in executable code cannot be confirmed from the fragment alone.

Confidence: 62%Severity: 58%
MalwareHIGH
references/injection-attacks.md

The fragment is a weaponized exploitation cheat-sheet covering SQL injection, SSTI, and command injection with explicit RCE, file read/write, persistence-style guidance, and reverse-shell/network-callback payloads. It is high-risk for supply-chain contexts because it provides immediately usable intrusion instructions rather than legitimate library functionality. No obfuscation is present; the primary concern is the overt malicious/hostile nature of the content and its potential for downstream misuse.

Confidence: 90%Severity: 95%
MalwareHIGH
references/file-upload-and-rce.md

This fragment is highly indicative of malicious payload content rather than benign source code: it embeds a crafted SVG `xlink:href` intended to trigger unsafe URI handling leading to `curl`/command-substitution-style exfiltration or command injection, and it includes a Zip Slip proof-of-concept targeting path traversal to write a script into a webroot via unsafe archive extraction. Any environment that renders such SVGs or extracts attacker-controlled archives without strict sanitization and safe extraction controls should treat this as a serious security risk.

Confidence: 72%Severity: 91%
MalwareHIGH
references/api-authorization-and-realtime.md

The provided text is an exploitation/testing playbook for API authorization bypass (BOLA/IDOR), function-level authorization failure (BFLA), CORS weaknesses, and WebSocket authorization issues. It contains actionable offensive guidance (credential/session replay across tenants, mass-assignment of privileged fields, and cross-origin data access verification). No actual dependency/library code is present to assess typical supply-chain malware behaviors (e.g., exfiltration, backdoors), so this review is limited to the artifact’s intent and actionability.

Confidence: 62%Severity: 70%
SecurityMEDIUM
references/waf-bypass.md

The provided fragment is not defensive or legitimate library code; it is an offensive, actionable WAF-bypass and exploitation instruction set for SQL injection and XSS, including concrete payload transformations and request/transport manipulation strategies. While it contains no executable malware in this snippet, its content would materially increase malicious capability if distributed via a software supply chain artifact. Treat as high security risk content; investigate provenance, package inclusion context, and whether it is used for benign security testing with appropriate safeguards.

Confidence: 90%Severity: 90%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:48 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fweb-exploit-technique%2F@28b03ec42b1afddb4cf14fe8818373fa7b2cbed2e1316acb12990312019af2e9
Security Audit — socket — web-exploit-technique