oauth-sso-attack
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as an OAuth attack playbook, but that stated purpose is itself offensive. It equips an AI agent to probe and exploit third-party authentication flows, including token interception and account-takeover paths, creating high misuse risk even without installers, binaries, or explicit exfiltration code.
Confidence: 94%Severity: 82%
Audit Metadata