offensive-api-abuse

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill’s footprint is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive exploitation capabilities against external systems. It materially increases the agent’s ability to perform harmful security testing actions, data extraction, SSRF, brute force, JWT abuse, and service disruption. No confirmed credential theft or hidden malware behavior is shown, but this is a high-risk offensive skill.

Confidence: 94%Severity: 95%
Audit Metadata
Analyzed At
Aug 27, 2026, 02:28 PM
Package URL
pkg:socket/skills-sh/snailsploit%2Fclaude-red%2Foffensive-api-abuse%2F@bc397e5b6480f9d562b640716151116fb6900063f9768398fdf4fba9240b4734
Security Audit — socket — offensive-api-abuse