broken-authentication
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as an offensive web-auth testing guide, but that stated purpose is itself high risk for an AI agent. It enables credential attacks, bypass techniques, and exploit workflows against external targets, with meaningful autonomy and indirect prompt-injection risk despite no obvious malware or exfiltration behavior.
Confidence: 93%Severity: 91%
Audit Metadata