cors-cross-origin-misconfiguration
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a CORS testing playbook, but it gives an AI agent explicit offensive security capability with exfiltration-focused payloads and internal-network attack scenarios. There is little supply-chain risk, but the skill’s operational security risk is high because it equips the agent to perform browser-based exploitation against targets.
Confidence: 94%Severity: 86%
Audit Metadata