graphql-security

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is GraphQL security hardening, but its actual footprint includes enabling offensive security actions and recommending third-party tools that may receive live auth headers. This is coherent with security testing, yet disproportionate for a general coding skill and high-risk for an AI agent because it can facilitate active exploitation and credential forwarding to external tools.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Apr 18, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/peterbamuhigire%2Fskills-web-dev%2Fgraphql-security%2F@f9b24ac8391b53a92bb131cbe130019925826cc4