web-vuln-ssti

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s behavior is coherent with its stated purpose, but that purpose is to perform offensive SSTI exploitation and confirm RCE on arbitrary web targets. There is little supply-chain concern in the core workflow, yet the exploit-focused capability, arbitrary network targeting, and optional forwarding of auth headers make it high security risk for an AI agent.

Confidence: 95%Severity: 93%
Audit Metadata
Analyzed At
Aug 19, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/woohyun212%2Fsecurity-skill%2Fweb-vuln-ssti%2F@629005bef09387ac2b5261ba6ecb491ebe0614e985201b17d7dad911e4f48311
Security Audit — socket — web-vuln-ssti