mitm-find-callback

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent but its purpose is to enable AI-driven offensive testing of payment callback vulnerabilities. Install trust is low concern, but the capability to inspect intercepted payment traffic and craft tampering requests makes the skill high security risk despite no clear malware or credential-harvesting behavior.

Confidence: 93%Severity: 83%
Audit Metadata
Analyzed At
Mar 23, 2026, 09:59 PM
Package URL
pkg:socket/skills-sh/instavm%2Fsecurity-skills%2Fmitm-find-callback%2F@82d6e2ec7fcfb0be973ed32154a086e3e6034624