request-smuggling

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is internally coherent as a request-smuggling exploitation skill, but it is high risk because it gives an AI agent offensive security procedures, impact-escalation paths, and one explicit exfiltration PoC. Install trust risk is moderate rather than critical: tool references are mostly documented/public security tools, though some are mutable or personal GitHub repos. No direct credential harvesting or hidden execution appears in the skill itself.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Frequest-smuggling%2F@6b6b4af44733712db71f444564d08ccea2fd2b325bb07fdfe9a0c450057eb2d3
Security Audit — socket — request-smuggling