hunt-ssti

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is an offensive security/exploitation playbook for SSTI, not a neutral framework guide. Its stated purpose and actual content align, but that purpose gives the agent high-risk capabilities: server-side code execution, SSRF to AWS metadata, and chaining into further attack skills. No malicious installer or hidden exfiltration is present, so it is not confirmed malware, but it is a high-risk skill that enables exploitation against external targets.

Confidence: 94%Severity: 90%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:31 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fhunt-ssti%2F@fe0b8bf70d53db88f2b97ef02406cbe74d30caac5e73da1a3e27219a2da45fca
Security Audit — socket — hunt-ssti