python-web-debug

Fail

Audited by Socket on Apr 22, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose and actual behavior align, but that purpose is explicitly to exploit Python web applications, extract secrets, defeat debugger protections, and achieve remote code execution on targets. There is little supply-chain concern, but the offensive capability and victim-data flows make the overall skill highly dangerous.

Confidence: 96%Severity: 94%
MalwareHIGH
references/werkzeug-pin-calculation.md

This fragment is an end-to-end, weaponized exploitation guide to compute Werkzeug Debugger PIN/authentication material by leaking host identifiers via SSRF/file://, then authenticate to the /console debugger and execute arbitrary OS commands via cmd=__import__('os').popen(...).read(). If such content were embedded in a dependency, it would represent a severe security risk and strong malicious intent.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:00 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fpython-web-debug%2F@996ccf0479b7f09163cc90b393d5ba5d7e32570a