waf-bypass-techniques
Audited by Socket on Jul 21, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill is internally consistent as an offensive WAF-evasion playbook, but that purpose gives an AI agent high-risk exploit-enabling capability. It has low supply-chain and credential risk, yet high operational risk because it teaches bypass of security controls and chaining into adjacent attack skills.
This fragment is not software that can run or steal/exfiltrate data; however, it is highly suspicious and materially harmful as supply-chain content because it provides an operational, vendor-specific WAF/CDN detection-and-bypass playbook with concrete payload examples. If distributed as part of a package/repo artifact, it should be treated as high-security-risk malicious facilitation rather than benign documentation.