ssti-hunter

Warn

Audited by Socket on Aug 22, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its stated purpose matches its content, but that purpose is to help an AI agent exploit SSTI through RCE, secret access, exfiltration, and post-exploitation steps, making it dangerous even without deceptive install behavior.

Confidence: 96%Severity: 94%
SecurityMEDIUM
references/payloads.md

High misuse/weaponization risk: this fragment is an offensive SSTI-to-RCE cheatsheet with explicit command execution, filesystem read, and OOB exfiltration payloads across many template engines, plus enumerated secret targets for post-compromise theft. It is not executable malware by itself, but as a distributable supply-chain artifact it meaningfully enables exploitation and data theft.

Confidence: 78%Severity: 86%
Audit Metadata
Analyzed At
Aug 22, 2026, 08:10 AM
Package URL
pkg:socket/skills-sh/rifteo%2Fskills%2Fssti-hunter%2F@cecd464046fe3ac093c0fb2793c45152d4bc5209dd272e40fac410c404ff1b05
Security Audit — socket — ssti-hunter