performing-csrf-attack-simulation

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent for a CSRF penetration-testing guide and mostly uses official tools, so it is not a credential-harvesting or supply-chain deception pattern. However, it gives an AI agent explicit offensive security procedures for exploiting authenticated sessions and validating attack success on real targets, which makes the overall risk high despite coherent purpose alignment.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Apr 7, 2026, 12:41 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-csrf-attack-simulation%2F@d4098d52ea1bfc1a7b39087c692d5c49a25baf1f