web-cache-deception

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as an offensive cache-attack playbook, but that stated purpose is itself high risk for an AI agent because it teaches exploitation, victim targeting, and sensitive-data retrieval workflows. No installer, credential harvesting path, or hidden exfiltration endpoint is present, so this is not confirmed malware; the main issue is offensive security enablement.

Confidence: 93%Severity: 88%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fweb-cache-deception%2F@bfd5482385d40724c63c220d70933edb863b245023a50f22ed16d7f2f3ea5e95
Security Audit — socket — web-cache-deception