api-security

Warn

Audited by Socket on Aug 28, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill’s offensive capabilities are aligned with its stated purpose, but that purpose is to enable active security exploitation by an AI agent. The main concerns are high-risk offensive use, mixed-trust third-party toolchain, and likely forwarding of tokens/scan data to external tools or SaaS platforms. Not confirmed malware, but it is a dangerous skill with substantial operational and supply-chain risk.

Confidence: 90%Severity: 89%
SecurityMEDIUM
references/rest-graphql-testing.md

This fragment is an offensive API exploitation/testing playbook with concrete GraphQL introspection/DoS/authorization-mutation attempts, REST injection/mass-assignment/parameter-pollution examples, and SSRF payloads targeting cloud metadata and file:// URIs. It does not itself provide evidence of dependency-level malware execution (no installation/runtime behavior shown), but it is highly dangerous as supply-chain-distributed attacker enablement material that can be used to attack real systems. Recommend treating it as high security risk if published or shipped with software, and ensuring it is not included in production artifacts or publicly distributed without clear defensive intent and access controls.

Confidence: 74%Severity: 88%
Audit Metadata
Analyzed At
Aug 28, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fapi-security%2F@ad395a3e826743fb9697e0e952dfec19dc5468a6c341fcb12b4e8b6aad1d14ce
Security Audit — socket — api-security