testing-cors-misconfiguration

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally coherent as a penetration-testing aid, but its actual footprint is high risk because it teaches active exploitation and explicit exfiltration of authenticated browser data to an attacker-controlled endpoint. Tooling references are mostly normal for security work, with moderate supply-chain concern from third-party scanners and an unverified `cors-scanner` reference, but the main concern is offensive-agent enablement and credentialed data theft workflows.

Confidence: 91%Severity: 81%
Audit Metadata
Analyzed At
Apr 7, 2026, 12:40 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-cors-misconfiguration%2F@d31007969aa6181b78c507c593896823997365a0