clickjacking

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a clickjacking attack playbook, but its actual purpose is to enable offensive security testing and exploit development by an AI agent. There are no supply-chain, credential, or exfiltration concerns in the provided text, so malware likelihood is low, but the offensive capability makes the skill high risk.

Confidence: 93%Severity: 86%
Audit Metadata
Analyzed At
Apr 9, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fclickjacking%2F@4f7af1977ec25267b6180abb53c66bc6c5f6e206