exploiting-prototype-pollution-in-javascript

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-consistent but high risk: it is an offensive security playbook that enables an AI agent to probe and exploit live targets for XSS, RCE, and authorization bypass. There is no clear evidence of credential theft, covert exfiltration, or deceptive publisher behavior, so it is not confirmed malware; however, as an AI-agent skill it grants dangerous exploit capability and should be classified as suspicious/high-risk.

Confidence: 93%Severity: 81%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:26 PM
Package URL
pkg:socket/skills-sh/mukul975%2Fanthropic-cybersecurity-skills%2Fexploiting-prototype-pollution-in-javascript%2F@45c37c878eafac70a37cc36802100b3553dc3f0db1957127f698b64818a7d3f0
Security Audit — socket — exploiting-prototype-pollution-in-javascript