websocket-attack

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能与其声明的 exploit 用途一致,但其实际作用是赋予 AI 代理主动 WebSocket 攻击能力,并包含明确的数据窃取示例与外传端点。无明显供应链问题,但作为 AI Agent Skill 属于高风险 offensive security 能力,应判定为可疑且危险。

Confidence: 96%Severity: 93%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:11 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fwebsocket-attack%2F@c06162bb2ad0720915cb7e22f910127e59bbb6cd