testing-for-open-redirect-vulnerabilities
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s behavior is coherent with its stated purpose, but that purpose is to provide offensive security capability to an AI agent. It enables active vulnerability testing, automated scanning, and external token/callback capture via attacker-controlled domains or Burp Collaborator, creating high real-world misuse risk even without clear evidence of hidden malware.
Confidence: 93%Severity: 90%
Audit Metadata