sast-idor

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK capability but not malware: the skill is internally consistent as a SAST IDOR detector and has no external installs, credential harvesting, or exfiltration paths. Its main risk is that it provides offensive security analysis capability to an AI agent and processes untrusted repository content while writing reports via autonomous subagents.

Confidence: 90%Severity: 79%
Audit Metadata
Analyzed At
Apr 8, 2026, 08:00 AM
Package URL
pkg:socket/skills-sh/utkusen%2Fsast-skills%2Fsast-idor%2F@d708f4ac86beb99dab48ebbc9a3e19f2ffd2a746