web-account-takeover

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent and has no supply-chain or credential-forwarding red flags, but it is an offensive security technique that teaches an AI agent how to achieve account takeover on web targets. Low malware indicators, moderate overall security risk due to exploit-focused capability.

Confidence: 91%Severity: 64%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-account-takeover%2F@f6fe724d4db50421888094efdd57612e63412e6a318b720e20a6a2a99e5e766c
Security Audit — socket — web-account-takeover