hunt-race-condition

Fail

Audited by Socket on Jul 4, 2026

3 alerts found:

Securityx2Malware
SecurityMEDIUM
references/payloads.md
MalwareHIGH
references/single-packet-attack.md

The provided fragment is not benign library logic; it is an offensive exploitation playbook and automation blueprint for manipulating HTTP/2/TLS framing and TCP write timing to force server-side race/atomicity failures and bypass rate limits or induce inconsistent business-state outcomes. While no typical credential-stealing/persistence code is present in the snippet itself, any dependency that implements these techniques would be high-risk for misuse in real-world attacks. Further review would require the actual surrounding package code to determine triggers, execution paths, and whether it performs automated targeting beyond the described methodology.

Confidence: 70%Severity: 90%
SecurityMEDIUM
SKILL.md
Audit Metadata
Analyzed At
Jul 4, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/jgamaraalv%2Fdelivery-loop%2Fhunt-race-condition%2F@fcf268262dec280fdb0c221050b6ee8cb00d5970b55c27357b61ecc4318bfd95
Security Audit — socket — hunt-race-condition