web-vuln-ssrf

Warn

Audited by Socket on Aug 19, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities match its stated purpose, but that purpose is an offensive security workflow for AI agents: it actively probes targets, bypasses SSRF filters, tests file/gopher access, and attempts cloud metadata and credential extraction. Install provenance is mostly legitimate, but the external OOB service, disabled TLS checks, sensitive token handling, and autonomous exploit guidance make the overall security risk high.

Confidence: 95%Severity: 88%
SecurityMEDIUM
REFERENCE.md

This fragment is non-executable instructional content that nonetheless provides highly actionable SSRF bypass payloads and cloud metadata exploitation paths (AWS/GCP/Azure), including clear escalation concepts toward credential theft and potential RCE via internal services. While it does not demonstrate runtime malicious behavior by itself, its operational specificity and offense-oriented nature make it a significant supply-chain security concern and should be treated as suspicious/harmful packaging content pending context on how the dependency is used.

Confidence: 80%Severity: 78%
Audit Metadata
Analyzed At
Aug 19, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/woohyun212%2Fsecurity-skill%2Fweb-vuln-ssrf%2F@f23012554a902c1537a702414891119f95720c5f212065af6ce46a997e406d57
Security Audit — socket — web-vuln-ssrf