api-mass-assignment

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent as a mass-assignment exploitation guide, but its purpose is offensive security: it instructs an AI agent to manipulate live API requests to gain privileges or alter other users' data. There is no install-chain or credential-exfiltration behavior, so this is not confirmed malware, but it is a high-risk exploit capability for an agent.

Confidence: 93%Severity: 83%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:02 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fapi-mass-assignment%2F@daa4c063c4db3b49480b015bb0b3b09962e16e2014f80a1e6e86f48824dd0f18
Security Audit — socket — api-mass-assignment