http-host-header-attacks

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Host header attack playbook, but its actual function is to enable offensive exploitation by an AI agent, including token capture via Burp Collaborator and SSRF/vhost abuse. Main risk is offensive security capability and induced data exfiltration, not supply-chain behavior.

Confidence: 94%Severity: 86%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:13 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fhttp-host-header-attacks%2F@95a4e1991d90690959f7e476cf83c9ee6fa7f6fe