jsreverser-mcp-javascript-reverse-engineering

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK but not confirmed malware. The skill's capabilities are mostly aligned with its reverse-engineering purpose, yet it gives an AI agent offensive browser-analysis powers, handles sensitive session/network data, forwards optional API keys to external code, and is installed from a GitHub repo whose relationship to the listed skill publisher is unclear.

Confidence: 85%Severity: 84%
Audit Metadata
Analyzed At
May 17, 2026, 12:26 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fjsreverser-mcp-javascript-reverse-engineering%2F@f72ec9d23081acb5ef3cb31e06b00712a7eb6783
Security Audit — socket — jsreverser-mcp-javascript-reverse-engineering