WebAssessment

Fail

Audited by Socket on Mar 5, 2026

2 alerts found:

Obfuscated FileAnomaly
Obfuscated FileHIGH
SKILL.md

The WebAssessment skill presents a coherent, modular approach to security assessment with recon, threat modeling, and pentest workflows. Its on-host orchestration, customization hooks, and local tool invocations are appropriate for an integrated security workflow but introduce non-trivial host IPC, runtime dependencies, and tight workspace coupling. The most notable risks are the mandatory localhost notification mechanism and the reliance on locally-sourced tooling (bun-based TS scripts) which require stringent access controls, version pinning, and integrity verification. Overall, risk is moderate; no explicit malicious activity is evident in this fragment, but the host-centric design warrants careful environment hardening and explicit authorization checks.

Confidence: 90%
AnomalyLOW
Workflows/pentest/Exploitation.md

This fragment is an explicit exploitation and PoC guide containing concrete payloads, tool commands, and reproduction steps for a broad set of web vulnerabilities (SQLi, XSS, CSRF, SSRF, XXE, file upload, auth/authorization faults). It is dual-use: appropriate and valuable for authorized security testing, but it materially lowers the effort for malicious actors if distributed without controls. There is no evidence of obfuscated code or an automated backdoor in the fragment itself, and no hard-coded credentials were found. Treat inclusion of this document in public packages or repositories as a moderate-to-high misuse risk; sanitize examples or restrict distribution to authorized testers.

Confidence: 75%Severity: 60%
Audit Metadata
Analyzed At
Mar 5, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/steffen025%2Fpai-opencode%2Fwebassessment%2F@d330b5cb91185bf1e5ca62e9468551da0312666d