business-logic-vulnerabilities
Audited by Socket on Jul 21, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS. The skill is internally consistent as an offensive business-logic testing guide, but its actual purpose is to enable exploitation techniques against web applications. There is little supply-chain or credential-harvesting evidence, yet the offensive security capability alone makes it high risk for an AI agent.
This is not a dependency/library implementation; it is an exploit-and-payload playbook containing actionable techniques to achieve OS command execution (DDE + web shell with `system($_GET...)`), file system compromise (path traversal to write `shell.php`), and data exfiltration (blind XXE OOB and JSONP/`sendBeacon`). If this content appeared inside a package, it would be a severe supply-chain maliciousness indicator. No benign library functionality is evidenced in the provided fragment.