oauth-sso-attack

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an OAuth attack playbook, but that stated purpose is itself offensive. It equips an AI agent to probe and exploit third-party authentication flows, including token interception and account-takeover paths, creating high misuse risk even without installers, binaries, or explicit exfiltration code.

Confidence: 94%Severity: 82%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Foauth-sso-attack%2F@b3241bbee78c1eaa519e51b43fde888cfc504ad1