HTML Injection Testing

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is dual-use: it provides detailed HTML injection testing techniques and ready-made exploitation templates (phishing, defacement, credential harvesting). While potentially useful for authorized security testing, its breadth and actionable payloads elevate dual-use risk and potential for misuse. In a supply-chain context, distribution of this content should be restricted to vetted, consent-based engagements with clear scoping and safety controls.

Confidence: 65%Severity: 78%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:22 AM
Package URL
pkg:socket/skills-sh/jpropato%2Fsiba%2Fhtml-injection-testing%2F@70bdd080b741cce2d75b3c1fae21b71710d619a7