llm-prompt-injection

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an LLM security testing playbook, but its actual footprint is an offensive technique library for jailbreaks, system-prompt extraction, tool abuse, and data exfiltration. There is no installer or credential-harvesting binary, so this is not confirmed malware, but it is a high-risk AI-agent exploit skill.

Confidence: 95%Severity: 82%
AnomalyLOW
JAILBREAK_PATTERNS.md

No evidence of traditional malware or supply-chain compromise exists in this module because it contains no executable behavior, I/O, networking, or credential/process access. However, the file is a highly actionable jailbreak/prompt-injection techniques catalog (including system-prompt extraction and escalation/encoding bypass patterns). Its primary risk is enabling abusive instruction crafting and increasing the likelihood of safety bypasses in downstream LLM deployments, especially if included in applications that generate or validate prompts.

Confidence: 78%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fllm-prompt-injection%2F@dafea40be0f2726e11df026691fc5f164a414ee895798c0595414ad46f9157f0
Security Audit — socket — llm-prompt-injection