saml-sso-attack
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its footprint is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive SAML attack capability against arbitrary targets. The main risk is exploit enablement and automated attack traffic, compounded by disabled TLS verification; there is little evidence of malware or hidden credential theft within the skill itself.
Confidence: 95%Severity: 91%
Audit Metadata