api-security
Audited by Socket on Jul 18, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill is purpose-aligned for API pentesting, but it gives an AI agent high-risk offensive security capabilities and directs immediate autonomous action against targets. It is not clearly malicious, but it is a high-risk exploit-oriented skill with supply-chain and execution-trust gaps.
No embedded malware implementation is present in the provided fragment (no executable logic, obfuscation, or persistence), but the content is highly weaponizable and explicitly instructs how to generate harmful GraphQL/REST/SSRF traffic (schema harvesting, DoS-like query overload, authorization bypass/destructive mutation attempts, NoSQL/mass-assignment/parameter pollution, and SSRF to cloud metadata/local files) via automation workflows. Treat as high misuse risk; additional context would be required to assess whether any actual executable code ships with the package.