html-injection-testing
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK. The skill’s footprint is coherent with its stated purpose, but that purpose is to help an AI agent perform offensive HTML-injection exploitation, including credential-harvesting phishing forms and defacement. Official tooling lowers supply-chain concern, yet the exploit and exfiltration guidance makes this a high-risk offensive security skill rather than a benign testing reference.
Confidence: 94%Severity: 91%
Audit Metadata