business-logic-vulnerabilities

Warn

Audited by Socket on May 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an offensive business-logic testing playbook, but that stated purpose is itself high risk for an AI agent. It does not show credential harvesting, malware delivery, or suspicious installers, yet it materially equips the agent to conduct exploitation against web applications and to expand into companion attack content.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
May 2, 2026, 05:27 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fbusiness-logic-vulnerabilities%2F@c6c62f2a443b51a1f4ea52b48313150fd04c32f7