waf-bypass-techniques
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill is internally consistent as an offensive security aid, but its purpose is to help an AI agent evade defenses and support exploitation. There is little supply-chain or credential risk, yet the exploit-enabling and transitive-skill behavior make the overall security risk high.
This fragment is not software that can run or steal/exfiltrate data; however, it is highly suspicious and materially harmful as supply-chain content because it provides an operational, vendor-specific WAF/CDN detection-and-bypass playbook with concrete payload examples. If distributed as part of a package/repo artifact, it should be treated as high-security-risk malicious facilitation rather than benign documentation.