web-vuln-ssti
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s behavior is coherent with its stated purpose, but that purpose is to perform offensive SSTI exploitation and confirm RCE on arbitrary web targets. There is little supply-chain concern in the core workflow, yet the exploit-focused capability, arbitrary network targeting, and optional forwarding of auth headers make it high security risk for an AI agent.
Confidence: 95%Severity: 93%
Audit Metadata