web-file-upload

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

HIGH risk offensive exploit skill. It is internally consistent with its stated purpose, but that purpose is to equip the agent to attack file-upload functionality with practical RCE/XSS/SSRF/XXE techniques. No supply-chain, credential-harvesting, or obfuscation signals are present, but the exploit enablement alone makes this unsafe.

Confidence: 93%Severity: 88%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-file-upload%2F@76eb83df7997150211d7b0375c12e6c235909aa35a8a8d4c680442270947b8e8
Security Audit — socket — web-file-upload