saml-sso-attack

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its footprint is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive SAML attack capability against arbitrary targets. The main risk is exploit enablement and automated attack traffic, compounded by disabled TLS verification; there is little evidence of malware or hidden credential theft within the skill itself.

Confidence: 95%Severity: 91%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fsaml-sso-attack%2F@e9f528b6cbead6167e320818f22d20afe764bb149390b7915f5c5272e327e7b5
Security Audit — socket — saml-sso-attack