waf-bypass-techniques

Warn

Audited by Socket on Jul 21, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an offensive WAF-evasion playbook, but that purpose gives an AI agent high-risk exploit-enabling capability. It has low supply-chain and credential risk, yet high operational risk because it teaches bypass of security controls and chaining into adjacent attack skills.

Confidence: 93%Severity: 89%
SecurityMEDIUM
WAF_PRODUCT_MATRIX.md

This fragment is not software that can run or steal/exfiltrate data; however, it is highly suspicious and materially harmful as supply-chain content because it provides an operational, vendor-specific WAF/CDN detection-and-bypass playbook with concrete payload examples. If distributed as part of a package/repo artifact, it should be treated as high-security-risk malicious facilitation rather than benign documentation.

Confidence: 88%Severity: 93%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fwaf-bypass-techniques%2F@52197739c06fd19a8f0d345cdd56d1a5687881ef7d34b4cdc1b308be724507b1
Security Audit — socket — waf-bypass-techniques