business-logic-vulnerabilities
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS. The skill is internally coherent as an offensive business-logic exploitation guide, but its actual footprint is a high-risk AI-agent security/exploit capability set: it teaches abuse of auth, payments, uploads, SSRF/XXE, cookie replay, and concurrent attacks against external targets. The flagged commands are mostly documentation, so this is not confirmed malware, but the offensive purpose plus third-party tool references and transitive expansion make it unsafe/high risk.
High-confidence malicious content: this fragment provides weaponized payloads for multiple real-world exploitation paths (XXE/OOB exfiltration, Office DDE command execution, path traversal webshell upload, race-window defense bypass, ZIP bomb DoS, spreadsheet formula injection, SSRF to metadata/internal services, CSRF, and JSONP-based data exfiltration). It is not indicative of a legitimate dependency; if this appeared in a package repository or build artifact, it would represent severe supply-chain/malware risk.