cors-cross-origin-misconfiguration

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a CORS exploitation/testing playbook, but its actual footprint is an offensive security guide for AI agents. It includes explicit data-exfiltration payloads, internal network targeting, and attack chains beyond ordinary defensive documentation, so overall security risk is high even though there is little evidence of malware or supply-chain abuse.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:24 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fcors-cross-origin-misconfiguration%2F@a103b3a7bc1759083dcbaac8527fde98dc38782b69b44e6bd443dddb30f59292
Security Audit — socket — cors-cross-origin-misconfiguration