business-logic-vulnerabilities

Fail

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an offensive business-logic exploitation guide, but its actual footprint is a high-risk AI-agent security/exploit capability set: it teaches abuse of auth, payments, uploads, SSRF/XXE, cookie replay, and concurrent attacks against external targets. The flagged commands are mostly documentation, so this is not confirmed malware, but the offensive purpose plus third-party tool references and transitive expansion make it unsafe/high risk.

Confidence: 93%Severity: 82%
MalwareHIGH
SCENARIOS.md

High-confidence malicious content: this fragment provides weaponized payloads for multiple real-world exploitation paths (XXE/OOB exfiltration, Office DDE command execution, path traversal webshell upload, race-window defense bypass, ZIP bomb DoS, spreadsheet formula injection, SSRF to metadata/internal services, CSRF, and JSONP-based data exfiltration). It is not indicative of a legitimate dependency; if this appeared in a package repository or build artifact, it would represent severe supply-chain/malware risk.

Confidence: 86%Severity: 95%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:25 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fbusiness-logic-vulnerabilities%2F@f6b286d0ff4b0f4e62f1b944f3097a3e32b5ed1e0936191ff12c156cdfe0163b
Security Audit — socket — business-logic-vulnerabilities