broken-access-control
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent and does not show credential theft, hidden execution, or malicious data flows, but it grants an AI agent explicit offensive security-testing guidance for access control and SSRF. Risk comes from exploit-oriented capability, not from exfiltration or installer abuse.
Confidence: 91%Severity: 74%
Audit Metadata