redirect-forge
Audited by Socket on Aug 22, 2026
2 alerts found:
MalwareSecuritySUSPICIOUS/HIGH-RISK. The skill is internally consistent as an offensive pentest playbook, but that purpose itself is high risk for an AI agent: it teaches exploitation, credential/token capture, phishing, SSRF chaining, and uses known interception endpoints. Third-party tool trust is also broad and unpinned. This is not confirmed malware, but it is a dangerous offensive capability set.
No executable dependency code is provided; the fragment reads as an OAuth `redirect_uri` exploitation guide with a token-catching example and token-exchange steps. While this does not prove that a real package contains malware, the content is highly sensitive and directly facilitates authorization code/token theft and account takeover if embedded into a software component’s runtime behavior or distributed as part of an attack toolchain. Treat as suspicious from a supply-chain perspective and require provenance/context review before use.