web-postmessage

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent and has no supply-chain or credential-forwarding issues, but it is an offensive security skill that teaches an AI agent to exploit postMessage flaws for XSS, data theft, and state change. Its main risk is enabling real exploit behavior, not hidden malware or deceptive data flows.

Confidence: 94%Severity: 78%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-postmessage%2F@43468043780fb548e5373fd246b3c65ab308421e51eb8244ae1a0492bdb95fb5
Security Audit — socket — web-postmessage