performing-ssrf-vulnerability-exploitation

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and behavior are internally consistent, but that purpose is to give an AI agent offensive SSRF exploitation capability against real systems, including cloud metadata and internal networks. Install trust is mostly normal, yet the enabled actions create high security risk despite limited evidence of malware or covert exfiltration.

Confidence: 95%Severity: 82%
Audit Metadata
Analyzed At
Mar 15, 2026, 09:40 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-ssrf-vulnerability-exploitation%2F@b510f1fb32fb7bc6dd82b5552b06bd497d22a616