web-saml

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an offensive SAML-auth attack technique, but it gives an AI agent explicit exploit guidance for authentication bypass and account impersonation. Install trust is relatively low-risk because no installer commands or credential forwarding are present, yet the capability itself is high-risk and disproportionate for general use.

Confidence: 92%Severity: 81%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-saml%2F@4ced92d53c9a5bb7c2fe8d20007a0290599b0c97cf23aa3248530896cb755c25
Security Audit — socket — web-saml