api-auth-attacks

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as an offensive API-authentication testing guide, but it gives an AI agent high-risk exploit capability against real services and involves live credential/token handling. There is no clear malicious exfiltration path or deceptive installer in the skill itself, so this is better classified as a high-risk offensive security skill rather than malware.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:02 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fapi-auth-attacks%2F@f4aaf16885ef3c079df128c649e6a8de4141e4c0750e197bfcfec45d22835ca1
Security Audit — socket — api-auth-attacks