IDOR Vulnerability Testing

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is clearly dual-use and oriented toward security testing of IDOR vulnerabilities. While this can be legitimate with explicit authorization, the material provides concrete exploitation techniques that could enable unauthorized access if misused. Given the dual-use risk and the explicit actionable attack patterns (ID manipulation, method switching, automated enumeration), the footprint is not proportionate to a benign defensive or educational purpose and warrants heightened scrutiny. The overall assessment is suspicious due to its facilitating of unauthorized data access, with remediation content not sufficiently isolating defensive use from offensive guidance.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:27 AM
Package URL
pkg:socket/skills-sh/hainamchung%2Fagent-assistant%2Fidor-vulnerability-testing%2F@8ecd7234dbb311d5dc41acdc819489877092fd17