http2-specific-attacks

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is internally consistent with its stated purpose, but that purpose is offensive exploitation. It is not malware and does not obviously exfiltrate credentials, yet it gives an AI agent high-risk security testing and DoS capabilities against arbitrary targets. Official-source evidence lowers supply-chain concern, but the overall skill should be classified as high-risk/suspicious due to offensive-agent enablement.

Confidence: 92%Severity: 91%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fhttp2-specific-attacks%2F@162bd7d5c4ec6740a8506a53276f7fb1836712e67c92d245daf1b5b08f9597b0
Security Audit — socket — http2-specific-attacks