web-lfi-path-traversal

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the scanner finding itself is benign documentation context, but the skill is an offensive exploit guide that teaches LFI/path traversal exploitation up to RCE, including a remote attacker-controlled archive path via pearcmd. No direct malware or credential theft is embedded in the skill file, yet its operational purpose is high-risk offensive security enablement for an AI agent.

Confidence: 92%Severity: 82%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-lfi-path-traversal%2F@bac984f3aae4520fac4923e5c7f47b3ae363dfb740ebdc0a7d9dbe6ef6b28dd9
Security Audit — socket — web-lfi-path-traversal