ssti
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent as an SSTI exploitation guide, but its actual footprint is an offensive-security playbook with step-by-step RCE and file-read payloads plus automation via tplmap. There is no clear credential theft or malicious exfiltration in the provided text, and the pre-execution alert looks like a false positive, but enabling an AI agent to perform exploitation against targets is high security risk by design.
Confidence: 90%Severity: 82%
Audit Metadata