ssti-server-side-template-injection

Fail

Audited by Socket on Jul 21, 2026

3 alerts found:

Securityx2Malware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill’s purpose and capabilities align as an exploitation playbook, but that purpose itself gives an AI agent offensive security capability: engine-specific RCE, credential harvesting, blind exfiltration, and persistence guidance. There is little supply-chain evidence in the snippet, but the operational footprint is high risk and inappropriate for general agent deployment.

Confidence: 92%Severity: 92%
MalwareHIGH
ENGINE_PAYLOADS.md

This module is highly actionable and weaponized: it provides cross-engine SSTI fingerprinting plus ready-to-deploy RCE, sensitive file read, and blind/OOB verification payloads. Even though it is documentation/Markdown (non-executable code by itself), including such content in a supply-chain dependency materially increases attacker capability to exploit vulnerable services. Treat as malicious/unsafe content.

Confidence: 90%Severity: 100%
SecurityMEDIUM
SCENARIOS.md

The provided file is not executable malware and contains no runtime logic, I/O, or process/network/file operations within the artifact itself. However, it is highly actionable exploitation guidance (SSTI/EL/OGNL/RCE and webshell-deployment recipes, including blind/OOB techniques) aimed at real-world targets. In a supply-chain context, the primary concern is misuse/weaponization and policy/compliance risk rather than proven malicious code execution in this specific snippet. Additional repository files would be required to assess whether any package scripts or runtime components are malicious.

Confidence: 66%Severity: 85%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fssti-server-side-template-injection%2F@68af733cce12ba1e2f481d3ceafcde002aaffe229f070b095c4ad518ba75b2df
Security Audit — socket — ssti-server-side-template-injection