web-ssti
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is an offensive security/exploitation guide that equips an AI agent to detect SSTI and escalate to RCE on target systems. The static command-injection hits are mostly documentation artifacts, but the underlying capability is intentionally high-risk and disproportionate for general agent use; the suggested external tool adds moderate supply-chain concern.
Confidence: 95%Severity: 88%
Audit Metadata