http-host-header-attacks
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a Host header attack playbook, but its actual function is to enable offensive exploitation by an AI agent, including token capture via Burp Collaborator and SSRF/vhost abuse. Main risk is offensive security capability and induced data exfiltration, not supply-chain behavior.
Confidence: 94%Severity: 86%
Audit Metadata