open-redirect

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's footprint is coherent with its stated purpose, but that purpose is to give an AI agent offensive exploitation guidance. It materially increases capability for phishing, token theft, and SSRF without defensive constraints, so it is high security risk even though it lacks malware-like installers or hidden exfiltration code.

Confidence: 94%Severity: 89%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fopen-redirect%2F@63d87ff5d74810f1c432d79827dfe59d2319fe3a6490602c6c7d592000ca0cfa
Security Audit — socket — open-redirect