web-cache-poisoning

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is internally consistent but high-risk because its stated purpose is offensive web exploitation. External tool references are same-org/official PortSwigger resources, and there is no suspicious installer, credential harvesting, or hidden data exfiltration. The main concern is that it equips an AI agent to perform active cache-poisoning/deception attacks with real impact on third-party targets.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-cache-poisoning%2F@269865417d649c8d91621921d3b1958024b6fcfa698f23c64573c894478f8d77
Security Audit — socket — web-cache-poisoning