testing-api-for-mass-assignment-vulnerability

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an API mass-assignment testing guide, but it is still high-risk because it equips an AI agent with offensive security actions that can modify real systems and attempt privilege escalation. Install trust is relatively normal and there is no clear credential theft or covert exfiltration, so this is not confirmed malware, but it is a dangerous security-testing skill that should only run under strict authorization and human approval.

Confidence: 92%Severity: 84%
Audit Metadata
Analyzed At
Mar 15, 2026, 03:58 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-api-for-mass-assignment-vulnerability%2F@0d45fd5b87e58ed6aba755b29e88dda544eb82d5