web-cypher-injection
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is purpose-aligned and not deceptive, but it is a high-risk offensive security capability: it teaches an AI agent to exploit Cypher injection for auth bypass, data theft, SSRF, and possible RCE. No supply-chain, credential-harvesting, or hidden exfiltration behavior is present; the primary concern is exploit enablement.
Confidence: 94%Severity: 87%
Audit Metadata