exploiting-prototype-pollution-in-javascript

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose and capabilities are internally consistent, but that purpose is to help an AI agent actively exploit vulnerabilities, including XSS, RCE, and authorization bypass on remote targets. Install trust is mostly normal and there is no strong evidence of credential harvesting or covert exfiltration, so this is not confirmed malware; however, as an offensive security/exploit skill for an agent, it poses high security risk.

Confidence: 93%Severity: 91%
Audit Metadata
Analyzed At
Mar 15, 2026, 09:40 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fexploiting-prototype-pollution-in-javascript%2F@41f62b33498658bfe780836ff6c038a853e4a4de