hunt-html-injection

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as a web-vulnerability hunting guide, but its purpose is to equip an AI agent with offensive security techniques, including credential-harvesting HTML injection and dangling-markup exfiltration. There is no notable installer or credential-forwarding supply-chain risk, but the offensive testing and exfiltration guidance make the skill high-risk.

Confidence: 93%Severity: 82%
Audit Metadata
Analyzed At
Aug 24, 2026, 11:02 PM
Package URL
pkg:socket/skills-sh/elementalsouls%2Fclaude-bughunter%2Fhunt-html-injection%2F@33be843f668a7917203bb62357563ac13f75cb8d01021b915e2d7d7a4e85fcdc
Security Audit — socket — hunt-html-injection