session-fixation

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and does not show credential exfiltration, hidden installs, or malicious data routing, but it is an offensive security skill that teaches an AI agent to detect and exploit session management weaknesses against live targets. Risk is driven by dual-use exploit capability and use of authenticated testing flows, not by malware-like behavior.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:37 PM
Package URL
pkg:socket/skills-sh/securityfortech%2Fhacking-skills%2Fsession-fixation%2F@180e70de26867c54bb41c36a37d68ec402cbd4ab6b0edc6e07694a2a98c7b1f2
Security Audit — socket — session-fixation