API Fuzzing for Bug Bounty

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's footprint is coherent with its stated purpose of API security testing and bug bounty guidance, but it includes high-risk exploitation patterns (IDOR, SQLi, command injection, XXE, SSRF, rate-limit bypass) and bypass techniques that could be misused. While no malicious payloads or remote installs are embedded, the content should be restricted to authorized engagements and accompanied by strong governance to prevent abuse. Overall risk is high for misuse, but the skill does not introduce covert data exfiltration or unauthorized software behavior by itself.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:51 AM
Package URL
pkg:socket/skills-sh/SivaG-lab%2Froth_mcp%2Fapi-fuzzing-for-bug-bounty%2F@b49da356b0e98f571cf65e6f0e89788dba35d1d2