idor-broken-object-authorization

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an attack playbook, but its actual purpose is to give an AI agent offensive security capabilities for exploiting authorization flaws, including enumeration and data-modifying actions on live targets. There are no notable supply-chain or credential-exfiltration signals, but the exploit-focused scope makes it high risk.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:22 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fidor-broken-object-authorization%2F@60ecfa9f005fa2601de7f01804f4821eb3bf91c7818e79108a85c4cadd900a26
Security Audit — socket — idor-broken-object-authorization