crlf-injection

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. The content is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive exploit capability for CRLF injection and related attack chains. No installer or credential-harvesting behavior is present, so this is not confirmed malware, but it is a high-risk security/exploit skill inappropriate for general agent use.

Confidence: 95%Severity: 88%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fcrlf-injection%2F@6f58fecd9e99ab30e4afa6d434ea1eb1a6a37951478b0f4c2fc66e71bbd20176
Security Audit — socket — crlf-injection