API Fuzzing for Bug Bounty
Warn
Audited by Socket on Feb 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
This skill is a detailed, coherent API penetration-testing/fuzzing guide that matches its stated purpose. However, it contains explicit exploitation payloads (XXE/LFI reading /etc/passwd, command injection, SQLi strings), external exfiltration examples (iplogger), DoS/port-scan techniques, and evasion advice (IP rotation). Those elements make it dual-use and potentially dangerous if used without authorization. Recommend marking as SUSPICIOUS for supply-chain distribution because it actively teaches concrete exploitation and exfiltration techniques and omits safeguards about authorized testing.
Confidence: 85%Severity: 65%
Audit Metadata