csrf-cross-site-request-forgery
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent as a CSRF testing playbook and shows no meaningful supply-chain or credential-theft behavior, but it gives an AI agent detailed offensive web-exploitation guidance with ready-to-use attack PoCs and chaining techniques. This makes it high risk as an AI-agent skill even though it is not confirmed malware.
Confidence: 93%Severity: 82%
Audit Metadata