testing-api-for-broken-object-level-authorization

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as a BOLA testing guide, but it gives an AI agent offensive security capabilities to use multiple credentials, enumerate object IDs, and perform unauthorized read/write/delete probes against live APIs. Install trust is mostly acceptable and data flows stay directed to the target API rather than an exfiltration service, so this is not confirmed malware; however, as an AI-agent skill it is high risk due to exploit-oriented behavior and real-world impact potential.

Confidence: 93%Severity: 86%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:54 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-api-for-broken-object-level-authorization%2F@c7776b25b26155fbeff83e6dcb367457c7ef6978