offensive-toctou

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive TOCTOU exploitation techniques against real systems. There is little supply-chain or credential risk, yet the operational security risk is high because it enables privilege escalation, auth bypass, container escape, and financial race exploitation.

Confidence: 94%Severity: 90%
Audit Metadata
Analyzed At
May 8, 2026, 03:37 AM
Package URL
pkg:socket/skills-sh/SnailSploit%2FClaude-Red%2Foffensive-toctou%2F@de0af209363913bcc09c87bcd9039b32bab67ce6
Security Audit — socket — offensive-toctou