prototype-pollution-advanced

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
KNOWN_GADGETS.md

This fragment is not a functional library; it is a prototype-pollution gadget/weaponization reference containing explicit RCE (child_process/NODE_OPTIONS) and XSS payload targeting and build-chain sabotage guidance. While it does not execute by itself here, its distribution in a dependency would be a significant supply-chain concern and warrants review of the broader package contents and provenance for any actual exploit/runtime behavior.

Confidence: 72%Severity: 62%
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its footprint is coherent with an offensive security playbook, but that stated purpose itself gives an AI agent concrete exploit capability for RCE and XSS against external targets. No clear credential theft or covert exfiltration is present in the text, so this is not confirmed malware, but it is a high-risk exploit skill with added transitive-skill and external-tool trust concerns.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fprototype-pollution-advanced%2F@c6a78f055be7e24da3bc16741a73bee56f05b7fb