clickjacking-hunter
Audited by Socket on Aug 22, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the skill is internally coherent as a clickjacking-testing guide, but its actual footprint is an offensive security capability for an AI agent, including PoC generation and bypass techniques that can drive real user-impact actions. Install trust is mostly ordinary, but the exploit-oriented purpose and attack flows make the overall skill high risk.
This module is best characterized as a clickjacking security scanner that escalates from passive header checks to generating and saving an actionable clickjacking proof-of-concept HTML (iframe overlay + decoy UI + adjustable opacity). No clear malware behaviors (credential theft, persistence, exfiltration, or obfuscated payloads) are present in the shown fragment, but the dual-use PoC creation significantly increases potential misuse. The fragment appears incomplete due to undefined references, so end-to-end runtime behavior may not fully match intent; however, the demonstrated PoC capability is clearly present.