http-host-header-attacks

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: internally coherent as a Host-header attack playbook, but it equips an AI agent with offensive security techniques, token-capture workflows, OAST routing, brute-force vhost discovery, and SSRF-style internal targeting. There is little supply-chain risk, but the operational security risk is high because the skill’s purpose is exploitation.

Confidence: 95%Severity: 86%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fhttp-host-header-attacks%2F@e8eef1831fb9cdd8ad7bb3aec37c395a1db932b2566ab20cd3b26e6c97ef103e
Security Audit — socket — http-host-header-attacks