business-logic-flaws
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent and uses legitimate tooling, but its actual function is to give an AI agent offensive web-application testing capabilities, including request tampering, race-condition abuse, and workflow bypass. There is little evidence of malware or covert exfiltration, yet the operational risk is high because the skill enables active exploitation against real targets.
Confidence: 91%Severity: 79%
Audit Metadata