dangling-markup-injection
Fail
Audited by Socket on Apr 9, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS/HIGH-RISK skill. It is internally consistent as a dangling markup exploitation playbook, but its purpose is overtly offensive: teaching an AI agent how to exfiltrate sensitive web application data and chain that theft into further attacks. No meaningful supply-chain risk is present, yet the skill materially increases offensive capability and should be treated as a high-risk security/exploit tool rather than benign guidance.
Confidence: 97%Severity: 96%
Audit Metadata