dangling-markup-injection

Fail

Audited by Socket on Apr 9, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS/HIGH-RISK skill. It is internally consistent as a dangling markup exploitation playbook, but its purpose is overtly offensive: teaching an AI agent how to exfiltrate sensitive web application data and chain that theft into further attacks. No meaningful supply-chain risk is present, yet the skill materially increases offensive capability and should be treated as a high-risk security/exploit tool rather than benign guidance.

Confidence: 97%Severity: 96%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fdangling-markup-injection%2F@e36368fa7b4ba3c9ce7b104e832d18f4290485d0