request-smuggling
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is internally coherent as a request-smuggling exploitation skill, but it is high risk because it gives an AI agent offensive security procedures, impact-escalation paths, and one explicit exfiltration PoC. Install trust risk is moderate rather than critical: tool references are mostly documented/public security tools, though some are mutable or personal GitHub repos. No direct credential harvesting or hidden execution appears in the skill itself.
Confidence: 89%Severity: 82%
Audit Metadata