fuzz

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and uses mostly legitimate install sources for ffuf, but it equips an AI agent with active offensive web fuzzing capabilities against external targets. Main risk is not hidden malware or exfiltration; it is enabling autonomous security scanning and authenticated probing with Bash. The ffuf install guidance looks legitimate, while the SecLists install note is less verifiable and mildly increases supply-chain concern.

Confidence: 91%Severity: 81%
Audit Metadata
Analyzed At
Apr 28, 2026, 05:52 AM
Package URL
pkg:socket/skills-sh/ariadoss%2Fsuperskills%2Ffuzz%2F@1707ef8fd74b2b74a323787c220acc69ae30019e