email-header-injection

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an offensive email-attack playbook, but that purpose itself is high risk for an AI agent. No installer or credential-harvesting behavior is present, yet the content meaningfully enables phishing, spoofing, and email exfiltration against external targets.

Confidence: 92%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Femail-header-injection%2F@293f84664596d614b47fe7e80ec5dcbca62d8a9d