ssti

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an SSTI exploitation guide, but its actual footprint is an offensive-security playbook with step-by-step RCE and file-read payloads plus automation via tplmap. There is no clear credential theft or malicious exfiltration in the provided text, and the pre-execution alert looks like a false positive, but enabling an AI agent to perform exploitation against targets is high security risk by design.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/securityfortech%2Fhacking-skills%2Fssti%2F@955cbaa5c30c63006fe4e40383090a929d260c7cdeaa998a96b99e57a6cbcbb8
Security Audit — socket — ssti