ssti-hunter
Warn
Audited by Socket on Aug 22, 2026
2 alerts found:
Securityx2SecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
High-risk offensive security skill. Its stated purpose matches its content, but that purpose is to help an AI agent exploit SSTI through RCE, secret access, exfiltration, and post-exploitation steps, making it dangerous even without deceptive install behavior.
Confidence: 96%Severity: 94%
Securityreferences/payloads.md
MEDIUMSecurityMEDIUM
references/payloads.md
High misuse/weaponization risk: this fragment is an offensive SSTI-to-RCE cheatsheet with explicit command execution, filesystem read, and OOB exfiltration payloads across many template engines, plus enumerated secret targets for post-compromise theft. It is not executable malware by itself, but as a distributable supply-chain artifact it meaningfully enables exploitation and data theft.
Confidence: 78%Severity: 86%
Audit Metadata