webhook-site

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for OAST/pentest work, but it enables an AI agent to collect and route sensitive callback data through a third-party interception service and provides offensive testing payloads. The main risk is intentional data capture/exfiltration plus agent-enabled security testing; install trust is secondary but weakened by mismatched CLI/container instructions.

Confidence: 94%Severity: 86%
MalwareHIGH
references/usage-matrix.md

This fragment is overwhelmingly consistent with malicious exploitation and exfiltration guidance. It includes clear, end-to-end patterns for blind XXE (HTTP/DNS exfil), command execution via RCE/SSTI-style payloads (leading to outbound HTTP/DNS egress), blind XSS cookie/session theft to an attacker-controlled webhook, and OAuth/SAML artifact capture via redirect/callback inspection. It also provides operational automation concepts for scalable attribution. Because the provided text does not include actual module implementation, provenance/placement within a package cannot be confirmed, but the content itself represents an extreme supply-chain security risk if it is distributed or executed as part of a dependency.

Confidence: 67%Severity: 100%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fwebhook-site%2F@0bf605e67e19f80477e491d130e291133af7cf9edae03196788e55ede1bc68f6
Security Audit — socket — webhook-site