API Fuzzing for Bug Bounty

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is a detailed, coherent API penetration-testing/fuzzing guide that matches its stated purpose. However, it contains explicit exploitation payloads (XXE/LFI reading /etc/passwd, command injection, SQLi strings), external exfiltration examples (iplogger), DoS/port-scan techniques, and evasion advice (IP rotation). Those elements make it dual-use and potentially dangerous if used without authorization. Recommend marking as SUSPICIOUS for supply-chain distribution because it actively teaches concrete exploitation and exfiltration techniques and omits safeguards about authorized testing.

Confidence: 85%Severity: 65%
Audit Metadata
Analyzed At
Feb 15, 2026, 07:58 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fapi-fuzzing-for-bug-bounty%2F@b49da356b0e98f571cf65e6f0e89788dba35d1d2