hunt-html-injection
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent as a web-vulnerability hunting guide, but its purpose is to equip an AI agent with offensive security techniques, including credential-harvesting HTML injection and dangling-markup exfiltration. There is no notable installer or credential-forwarding supply-chain risk, but the offensive testing and exfiltration guidance make the skill high-risk.
Confidence: 93%Severity: 82%
Audit Metadata