web-ssrf

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent as an SSRF exploitation guide, but it gives an AI agent explicit offensive security instructions, uses OAST callback collectors, and describes escalation to cloud metadata, credential theft, and RCE. There is little supply-chain concern, but the capability itself is high risk and inappropriate outside authorized security testing.

Confidence: 95%Severity: 91%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-ssrf%2F@cd9324b4ba269dd5119562eedf44a5afcff6cfa02403aee70ece15e1b5290982
Security Audit — socket — web-ssrf