sast-fileupload

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as a file-upload SAST workflow and shows no credential harvesting, third-party routing, or suspicious installer behavior. However, it is a high-risk offensive-security skill because it directs an AI agent to discover and verify exploitation paths for insecure file uploads, including dynamic test payloads; the static curl/backtick findings are documentation artifacts rather than active malware indicators.

Confidence: 92%Severity: 76%
Audit Metadata
Analyzed At
Sep 20, 2026, 03:35 AM
Package URL
pkg:socket/skills-sh/utkusen%2Fsast-skills%2Fsast-fileupload%2F@5979cac8d910ee9502c1ad44d55c217b265f7b0362336b034082b59a83645823
Security Audit — socket — sast-fileupload