http-host-header-attacks
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as an exploit methodology, but that purpose is high-risk because it equips an AI agent to perform offensive web attacks with real-world impact, including token theft and SSRF/vhost abuse. There is little supply-chain concern, but the offensive capability itself makes the skill dangerous.
Confidence: 94%Severity: 91%
Audit Metadata