offensive-graphql

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive GraphQL attack techniques. There is no clear credential-harvesting or hidden malware behavior, yet the exploit, brute-force, DoS, and exfiltration guidance makes it a high-risk offensive-security skill rather than a benign development aid.

Confidence: 89%Severity: 83%
Audit Metadata
Analyzed At
Aug 27, 2026, 02:28 PM
Package URL
pkg:socket/skills-sh/snailsploit%2Fclaude-red%2Foffensive-graphql%2F@bb5760236fdda667e6bb064c44400dd911d426cab5fa2dfda894f193fde0fcfe
Security Audit — socket — offensive-graphql