expression-language-injection

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is not malware by itself, but it is a high-risk offensive exploitation guide for AI agents. Its capabilities are coherent with its stated purpose, yet that purpose is to detect, weaponize, and operationalize EL injection into RCE against live systems, so it should be classified as SUSPICIOUS/HIGH RISK rather than benign.

Confidence: 95%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fexpression-language-injection%2F@22fe01a6a5d6655590f2f5a64c00ad45ad4f1675