jndi-injection

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its content is internally consistent with its stated purpose, but that purpose is to help an AI agent exploit JNDI/Log4Shell vulnerabilities, evade defenses, and exfiltrate secrets to attacker-controlled infrastructure. Not covert malware by itself, but clearly dangerous and unsuitable for general agent use.

Confidence: 94%Severity: 93%
Audit Metadata
Analyzed At
Apr 9, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fjndi-injection%2F@bde8d102f84bb129b2b3e79ccac419c3b709c1d4