testing-for-broken-access-control
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned as a broken-access-control testing guide, and its tool references are mostly legitimate, but it gives an AI agent offensive security capabilities with authenticated enumeration and state-changing attack workflows. There is no strong evidence of malware or covert exfiltration, yet the operational risk is high because the skill can be used to probe or exploit real systems if authorization is absent or misrepresented.
Confidence: 90%Severity: 82%
Audit Metadata