web-command-injection

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

High-risk offensive exploit skill. It is internally consistent with its stated purpose, but that purpose is to equip an AI agent to execute command injection attacks, verify compromise via timing/OOB channels, and exfiltrate proof from target systems. No clear malicious installer or credential theft is present, but the operational capability is dangerous and disproportionate for general agent use.

Confidence: 95%Severity: 94%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-command-injection%2F@28819e38fb2b00601c1374c15eb509707b192c746274785bca1c3f1cb2d0c0d6
Security Audit — socket — web-command-injection