hunt-nextjs
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is coherent with its stated purpose, but the purpose itself is high risk: it equips an AI agent to conduct active security testing and exploitation of Next.js targets, including SSRF confirmation through known callback collectors. No hidden installer, credential theft flow, or malware behavior is evident, but the offensive network actions make the skill suspicious and dangerous in deployment.
Confidence: 92%Severity: 87%
Audit Metadata