idor-broken-object-authorization

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its footprint is coherent with its stated purpose, but the purpose itself is to equip an AI agent with offensive security testing techniques against authorization controls. There is no clear malware, credential theft, or suspicious installer behavior, yet the skill materially increases the agent's ability to probe and exploit live targets.

Confidence: 93%Severity: 82%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fidor-broken-object-authorization%2F@60ecfa9f005fa2601de7f01804f4821eb3bf91c7818e79108a85c4cadd900a26
Security Audit — socket — idor-broken-object-authorization