web-deserialization

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an insecure-deserialization exploitation guide, but its actual function is to help an AI agent generate and deliver RCE payloads against target systems. No clear credential harvesting or deceptive install path is present, and the .config finding is contextual, but the offensive-security purpose and OOB callback workflow make it high security risk.

Confidence: 91%Severity: 79%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-deserialization%2F@b046ba8263e8d26427e09fa4cc9927c2aa0c3ee5ad46918ba4dcc3078292f91d
Security Audit — socket — web-deserialization