http-host-header-attacks
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is a coherent offensive security playbook, not malware, but it gives an AI agent practical exploit procedures for Host-header attacks, vhost brute-forcing, SSRF routing tests, and token-capture workflows. The scanner's command-injection and concealment signals are mostly false positives, while the main risk comes from the skill's explicit attack capability and use of a callback capture service during exploitation.
Confidence: 91%Severity: 82%
Audit Metadata