prototype-pollution

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a prototype-pollution exploitation playbook, but that stated purpose itself gives the AI agent high-risk offensive security capability against external targets. There are no strong malware signals such as secret harvesting, hidden execution, or malicious installers, so this is best classified as high security risk rather than confirmed malware.

Confidence: 93%Severity: 79%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:15 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fprototype-pollution%2F@9db3fb71da8e1266828d34c221c36754240a72bf59449d664da839d6878f49b3
Security Audit — socket — prototype-pollution