idor-testing
Warn
Audited by Socket on Jun 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent as an IDOR testing guide, but its actual capability is offensive security enablement for an AI agent: it teaches exploitation, enumeration, and bypass methods against web applications. There is little supply-chain risk and no obvious credential harvesting, but the skill materially increases an agent's ability to conduct unauthorized security testing and access-control abuse.
Confidence: 92%Severity: 86%
Audit Metadata