upload-insecure-files

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an offensive upload-exploitation playbook, but that purpose itself gives an AI agent high-risk attack capability. The main concern is offensive security enablement plus transitive loading of related skills, not malware or installer abuse.

Confidence: 94%Severity: 88%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:28 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fupload-insecure-files%2F@ef36b04a9fdc3bd5f78ab819c4acda8f771160c340d52afdc34e45fa45266e76
Security Audit — socket — upload-insecure-files