macos-process-injection

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install path itself is low-risk and consistent with official Electron tooling, but the skill’s stated purpose is to give an AI agent operational process-injection and exploitation guidance on macOS, including shell execution, Mach/XPC abuse, Electron code execution, and persistence-adjacent tampering. That offensive capability is fundamentally high-risk for an agent skill even without overt credential theft or malicious installers.

Confidence: 95%Severity: 86%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fmacos-process-injection%2F@42632d918eeb50bda281fdd32f85c6a5f5f2dae1fa9b27f5ab50b3646e1f89ca
Security Audit — socket — macos-process-injection