Broken Authentication Testing
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is coherent with its stated purpose, but that purpose is to give an AI agent offensive authentication-testing capability. There is no obvious hidden exfiltration endpoint or suspicious installer, yet the skill enables brute force, credential stuffing, MFA bypass, and session hijacking techniques with real-world impact. Classified as SUSPICIOUS due to high-risk offensive security functionality for an agent.
Confidence: 90%Severity: 78%
Audit Metadata