cors-misconfig
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent as a CORS exploitation guide, but its actual footprint is offensive: it teaches an AI agent to validate, weaponize, and exfiltrate authenticated cross-origin data from targets. Install trust is low concern, yet the explicit attacker PoCs and exfiltration flows make this a high-risk offensive security skill rather than a benign documentation aid.
Confidence: 95%Severity: 86%
Audit Metadata