PromptInjection

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s offensive-security purpose matches its capabilities, but it grants an AI agent high-risk prompt-injection, jailbreak, and system-prompt-extraction behaviors. The mandatory hidden curl notification before any other action is unnecessary to core function and adds trust concerns, though there is no strong evidence of malware or external credential theft in the provided text.

Confidence: 93%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:49 AM
Package URL
pkg:socket/skills-sh/danielmiessler%2Fpersonal_ai_infrastructure%2Fpromptinjection%2F@653643830269f55e92fdf75d7d4e241cbf5b98a1