idor-testing
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent, but its stated purpose is to give an AI agent offensive web exploitation capability for IDOR discovery and abuse. There is little supply-chain risk from the documented dependencies, yet the operational risk is high because the skill directly enables autonomous security testing and unauthorized data access attempts against web applications.
Confidence: 89%Severity: 84%
Audit Metadata