jsreverser-mcp-javascript-reverse-engineering

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for reverse engineering, but it is a high-risk security-research capability set with broad browser instrumentation, session/state handling, and indirect prompt-injection exposure. Main concerns are proportionality of offensive capabilities for an AI agent, third-party repo trust mismatch with the named publisher, and optional forwarding of analyzed code/data to external LLM providers.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:35 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fjsreverser-mcp-javascript-reverse-engineering%2F@def35a36c8b31a2946be8983c269e58b67fc2107178c0a8791e57c3489883bb7
Security Audit — socket — jsreverser-mcp-javascript-reverse-engineering