csrf-cross-site-request-forgery

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as an offensive CSRF attack playbook, but that purpose gives an AI agent concrete exploit capability against web targets. There are no notable supply-chain or credential-exfiltration signals, yet the offensive security scope alone makes overall risk high.

Confidence: 93%Severity: 86%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fcsrf-cross-site-request-forgery%2F@e48547a5c797f4fd5ead9fd94bc1f46f7e74764f64b7c4e3b4850a526a52485f
Security Audit — socket — csrf-cross-site-request-forgery