sast-fileupload
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent as a file-upload SAST workflow and shows no credential harvesting, third-party routing, or suspicious installer behavior. However, it is a high-risk offensive-security skill because it directs an AI agent to discover and verify exploitation paths for insecure file uploads, including dynamic test payloads; the static curl/backtick findings are documentation artifacts rather than active malware indicators.
Confidence: 92%Severity: 76%
Audit Metadata