exploiting-http-request-smuggling

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as a penetration-testing skill, but its actual function is to equip an AI agent with offensive web exploitation techniques that can harm live users and bypass access controls. Install trust is mixed: official Burp/curl references are normal, but unpinned GitHub-source security tools increase supply-chain risk. No hidden credential harvesting or unrelated data exfiltration path is evident, so this is better classified as high-risk offensive capability rather than confirmed malware.

Confidence: 93%Severity: 91%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:30 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fexploiting-http-request-smuggling%2F@80d5a45e505fbc422eb69050dcfe32c2ff830eb4