graphql-and-hidden-parameters
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill: its footprint is coherent with its stated purpose, but that purpose is to equip the agent for offensive security testing against APIs. There is no clear malware behavior, credential theft, or suspicious installer path in this text, yet the skill materially increases the agent's ability to probe authorization flaws and hidden functionality on live targets.
Confidence: 87%Severity: 78%
Audit Metadata