exploiting-prototype-pollution-in-javascript
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-consistent but high risk: it is an offensive security playbook that enables an AI agent to probe and exploit live targets for XSS, RCE, and authorization bypass. There is no clear evidence of credential theft, covert exfiltration, or deceptive publisher behavior, so it is not confirmed malware; however, as an AI-agent skill it grants dangerous exploit capability and should be classified as suspicious/high-risk.
Confidence: 93%Severity: 81%
Audit Metadata