api-security

Warn

Audited by Socket on Jul 18, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for API pentesting, but it gives an AI agent high-risk offensive security capabilities and directs immediate autonomous action against targets. It is not clearly malicious, but it is a high-risk exploit-oriented skill with supply-chain and execution-trust gaps.

Confidence: 88%Severity: 84%
SecurityMEDIUM
references/rest-graphql-testing.md

No embedded malware implementation is present in the provided fragment (no executable logic, obfuscation, or persistence), but the content is highly weaponizable and explicitly instructs how to generate harmful GraphQL/REST/SSRF traffic (schema harvesting, DoS-like query overload, authorization bypass/destructive mutation attempts, NoSQL/mass-assignment/parameter pollution, and SSRF to cloud metadata/local files) via automation workflows. Treat as high misuse risk; additional context would be required to assess whether any actual executable code ships with the package.

Confidence: 76%Severity: 86%
Audit Metadata
Analyzed At
Jul 18, 2026, 08:17 AM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fapi-security%2F@9d72f94fab739150e9f6b3ef2fb9c069ecd9cfa739f4fb773c6a717557aa4dfc
Security Audit — socket — api-security