exploiting-oauth-misconfiguration

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, but the purpose itself is to equip an AI agent with offensive OAuth exploitation techniques, including credential capture and account-takeover paths. Data flows to attacker-controlled endpoints are intentional and disproportionate for a general agent skill.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fexploiting-oauth-misconfiguration%2F@a11b18708d3964018eff068328a6736fb300b7be