testing-oauth2-implementation-flaws

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive OAuth/OIDC testing capability against live systems. Tool references are mostly legitimate, with moderate supply-chain caution for third-party Burp extensions. Not confirmed malware, but high security risk due to exploit-oriented functionality and use of live tokens/codes during testing.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Mar 15, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-oauth2-implementation-flaws%2F@4244b166e6c74f95f57814f978e1a4ade404583b