web-vuln-graphql

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a GraphQL security-testing guide, but its actual function is to give an AI agent offensive testing techniques against live targets, including authorization bypass, brute-force/rate-limit bypass, and DoS probes. No strong malware or credential-stealing behavior is present, but the capability set is high-risk by design.

Confidence: 95%Severity: 86%
Audit Metadata
Analyzed At
Aug 19, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/woohyun212%2Fsecurity-skill%2Fweb-vuln-graphql%2F@34876e910cd6faae76f71612337c7eda3d0f858ec212df6fdc4ea80ebd1432e9
Security Audit — socket — web-vuln-graphql