web-csp-bypass
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK. The skill is narrowly focused on offensive web exploitation: bypassing CSP to execute XSS or exfiltrate data. Its capabilities are aligned with that offensive purpose, but that purpose itself gives an AI agent exploit-enablement guidance and explicit data-theft techniques. No supply-chain or credential-forwarding issues are present; the main risk is security misuse.
Confidence: 91%Severity: 84%
Audit Metadata