waf-bypass-techniques

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an offensive security aid, but its purpose is to help an AI agent evade defenses and support exploitation. There is little supply-chain or credential risk, yet the exploit-enabling and transitive-skill behavior make the overall security risk high.

Confidence: 92%Severity: 84%
SecurityMEDIUM
WAF_PRODUCT_MATRIX.md

This fragment is not software that can run or steal/exfiltrate data; however, it is highly suspicious and materially harmful as supply-chain content because it provides an operational, vendor-specific WAF/CDN detection-and-bypass playbook with concrete payload examples. If distributed as part of a package/repo artifact, it should be treated as high-security-risk malicious facilitation rather than benign documentation.

Confidence: 88%Severity: 93%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fwaf-bypass-techniques%2F@52197739c06fd19a8f0d345cdd56d1a5687881ef7d34b4cdc1b308be724507b1
Security Audit — socket — waf-bypass-techniques