web-csp-bypass

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill is narrowly focused on offensive web exploitation: bypassing CSP to execute XSS or exfiltrate data. Its capabilities are aligned with that offensive purpose, but that purpose itself gives an AI agent exploit-enablement guidance and explicit data-theft techniques. No supply-chain or credential-forwarding issues are present; the main risk is security misuse.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-csp-bypass%2F@46049eff3811e4ac500a69910aa2ef6a7a7722605911efd58db8c313ccaca3a8
Security Audit — socket — web-csp-bypass