spa-reverse-engineer

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill fragment is a high-risk toolkit for SPA reverse engineering, capable of extracting runtime state and intercepting network traffic. While it could be deployed for legitimate debugging and tooling, numerous capabilities (state-hook interception, request body logging, persistent payload storage, and targeted live-site interception) pose substantial privacy and security risks if misused or deployed without explicit user consent and safeguards. Recommend implementing strict consent prompts, scope-limiting defaults, data minimization, and robust auditing before use in production environments. Treat as SUSPICIOUS-to-UNRESTRICTED for general distribution; ensure governance controls if used in legitimate contexts.

Confidence: 65%Severity: 66%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:54 PM
Package URL
pkg:socket/skills-sh/pv-udpv%2Fpplx-sdk%2Fspa-reverse-engineer%2F@2e852dd5f5d9fbd7cdb9a434eaaa7acc92560dae