exploiting-template-injection-vulnerabilities

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities align as an offensive pentesting skill, but it equips an AI agent to perform exploit development and active RCE/file-read attempts against targets. The main risks are offensive security enablement, credential forwarding to third-party tools, and unpinned third-party installs; this is high security risk but not confirmed malware.

Confidence: 94%Severity: 89%
Audit Metadata
Analyzed At
Apr 9, 2026, 10:29 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fexploiting-template-injection-vulnerabilities%2F@057db07800133db4fb0d835720122c2a3a56c7a1