idor-broken-object-authorization
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as an attack playbook, but its actual purpose is to give an AI agent offensive security capabilities for exploiting authorization flaws, including enumeration and data-modifying actions on live targets. There are no notable supply-chain or credential-exfiltration signals, but the exploit-focused scope makes it high risk.
Confidence: 92%Severity: 78%
Audit Metadata