hunt-csrf
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a CSRF hunting guide, but its actual purpose is to equip an AI agent with offensive security capabilities against live authenticated targets. There is no clear malware or credential-harvesting server, yet the exploit-focused scope, session-cookie handling, and autonomous testing guidance make it high-risk.
Confidence: 92%Severity: 86%
Audit Metadata