http-host-header-attacks

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an exploit methodology, but that purpose is high-risk because it equips an AI agent to perform offensive web attacks with real-world impact, including token theft and SSRF/vhost abuse. There is little supply-chain concern, but the offensive capability itself makes the skill dangerous.

Confidence: 94%Severity: 91%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fhttp-host-header-attacks%2F@0d962d2160e206ece8736818d2dce78441d6e3c4