security-vuln-gauntlet

Warn

Audited by Socket on Aug 14, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its purpose is to equip an AI agent for vulnerability research and exploit PoC development, which is a high-risk offensive capability. It does not show malware behavior, credential theft, exfiltration, or supply-chain abuse in the provided text.

Confidence: 91%Severity: 78%
SecurityMEDIUM
references/example-web-run.md

The endpoint directly uses a user-supplied query parameter to build a filesystem path and passes it to res.sendFile without enforcing that the resolved path stays within '/srv/reports'. This enables directory traversal (CWE-22) and potentially arbitrary file read for files accessible to the application process. No clear malware/backdoor behavior is evident in the snippet; the primary issue is a severe input-to-file-serving validation flaw.

Confidence: 72%Severity: 80%
Audit Metadata
Analyzed At
Aug 14, 2026, 10:50 PM
Package URL
pkg:socket/skills-sh/trilwu%2Fgauntlet-loop-skills%2Fsecurity-vuln-gauntlet%2F@e0c1acf8d0f3656135af9f5efe8131dba5878774f1708c83581516411226dd58
Security Audit — socket — security-vuln-gauntlet