ssti-detect

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent in purpose, but its purpose is to equip the agent with offensive web vulnerability testing capability. There is no clear credential theft, exfiltration, or malicious supply-chain behavior in the text, so this is not confirmed malware; the main risk is enabling AI-driven security probing against targets.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Mar 25, 2026, 12:36 PM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fssti-detect%2F@63e74ede3208e5604d196fa1b2747162678cdca1