testing-for-broken-access-control

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned as a broken-access-control testing guide, and its tool references are mostly legitimate, but it gives an AI agent offensive security capabilities with authenticated enumeration and state-changing attack workflows. There is no strong evidence of malware or covert exfiltration, yet the operational risk is high because the skill can be used to probe or exploit real systems if authorization is absent or misrepresented.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:54 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-for-broken-access-control%2F@7b1522bdafe8d853fd90e3e36dd025b6e1dfd695