web-postmessage
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent and has no supply-chain or credential-forwarding issues, but it is an offensive security skill that teaches an AI agent to exploit postMessage flaws for XSS, data theft, and state change. Its main risk is enabling real exploit behavior, not hidden malware or deceptive data flows.
Confidence: 94%Severity: 78%
Audit Metadata