testing-for-open-redirect-vulnerabilities

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior is coherent with its stated purpose, but that purpose is to provide offensive security capability to an AI agent. It enables active vulnerability testing, automated scanning, and external token/callback capture via attacker-controlled domains or Burp Collaborator, creating high real-world misuse risk even without clear evidence of hidden malware.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:54 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-for-open-redirect-vulnerabilities%2F@487574ffe2cb9f166558257ef4e7ad6a06037b97