testing-for-open-redirect-vulnerabilities

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill is internally consistent as an open-redirect testing guide, but its actual footprint is offensive: it equips an AI agent to execute exploit testing and to chain findings into phishing, token theft, SSO abuse, and cookie exfiltration. Official tools reduce supply-chain concern, yet the use of attacker-controlled domains and Burp Collaborator makes the data-flow risk severe and disproportionate for normal agent use.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Apr 9, 2026, 06:50 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-for-open-redirect-vulnerabilities%2F@bac857c4a898911a9362d9a0723b98882a120c8b