web-ssti

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is an offensive security/exploitation guide that equips an AI agent to detect SSTI and escalate to RCE on target systems. The static command-injection hits are mostly documentation artifacts, but the underlying capability is intentionally high-risk and disproportionate for general agent use; the suggested external tool adds moderate supply-chain concern.

Confidence: 95%Severity: 88%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-ssti%2F@023268fdf33a4de121521ae2c6c2b2451a47361b8c3f481b3480f1ce7fa186f9
Security Audit — socket — web-ssti