broken-access-control

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent and does not show credential theft, hidden execution, or malicious data flows, but it grants an AI agent explicit offensive security-testing guidance for access control and SSRF. Risk comes from exploit-oriented capability, not from exfiltration or installer abuse.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Sep 15, 2026, 08:15 PM
Package URL
pkg:socket/skills-sh/scholarly360%2Fowasp-top10-web-skills%2Fbroken-access-control%2F@3527fb6c4719da24d428871a360bc341c043ff2266f00296d1c48a2ecc5fb0ce
Security Audit — socket — broken-access-control