web-pentest

Fail

Audited by Socket on Jun 29, 2026

3 alerts found:

SecurityMalwareAnomaly
SecurityMEDIUM
SKILL.md
MalwareHIGH
references/ssti-deserialization.md

This fragment is an exploit-oriented payload/detection playbook that materially facilitates achieving server-side code execution via SSTI, prototype pollution→RCE, and insecure deserialization. It includes actionable multi-runtime RCE payloads, fileless execution via NODE_OPTIONS/data: URI concepts, deserialization gadget-chain targeting, and attacker-controlled outbound callback examples. While the snippet does not prove how/if a specific package would execute code, its presence in a dependency would represent an extremely high supply-chain security concern and should be treated as suspicious until the actual package source and install/runtime behaviors are verified.

Confidence: 78%Severity: 95%
AnomalyLOW
references/auth-api-access-control.md

No runnable dependency code is present in the provided fragment; it is an offensive security/testing playbook with concrete instructions and payload examples for auth bypass, session/privilege compromise, GraphQL abuse/DoS, IDOR/BOLA enumeration, mass assignment, and race-condition exploitation. While malicious payload behavior (exfiltration/persistence) cannot be confirmed without the referenced script implementations, the content’s operational nature and explicit exploitation guidance indicate high misuse risk and warrant reviewing the repository’s actual script code and packaging intent before any use in production or by developers.

Confidence: 78%Severity: 65%
Audit Metadata
Analyzed At
Jun 29, 2026, 12:59 PM
Package URL
pkg:socket/skills-sh/hypnguyen1209%2Foffensive-claude%2Fweb-pentest%2F@5c062f6eefbac5b27e6e156f891570bb2a9fa78be262ff2e8c56a18c869e50b2
Security Audit — socket — web-pentest