business-logic-flaws

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent and uses legitimate tooling, but its actual function is to give an AI agent offensive web-application testing capabilities, including request tampering, race-condition abuse, and workflow bypass. There is little evidence of malware or covert exfiltration, yet the operational risk is high because the skill enables active exploitation against real targets.

Confidence: 91%Severity: 79%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/securityfortech%2Fhacking-skills%2Fbusiness-logic-flaws%2F@f2d6253af3d805f4b90fe9ec3b5bc324a21b01a18b9f225c14a24aeac8085476
Security Audit — socket — business-logic-flaws