web-cypher-injection

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is purpose-aligned and not deceptive, but it is a high-risk offensive security capability: it teaches an AI agent to exploit Cypher injection for auth bypass, data theft, SSRF, and possible RCE. No supply-chain, credential-harvesting, or hidden exfiltration behavior is present; the primary concern is exploit enablement.

Confidence: 94%Severity: 87%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-cypher-injection%2F@41967d44020c2d08df23d426657e2587be75cdc16c6f305494a12772da4474cb
Security Audit — socket — web-cypher-injection