clickjacking-hunter

Warn

Audited by Socket on Aug 22, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a clickjacking-testing guide, but its actual footprint is an offensive security capability for an AI agent, including PoC generation and bypass techniques that can drive real user-impact actions. Install trust is mostly ordinary, but the exploit-oriented purpose and attack flows make the overall skill high risk.

Confidence: 89%Severity: 82%
AnomalyLOW
scripts/clickjacking_agent.py

This module is best characterized as a clickjacking security scanner that escalates from passive header checks to generating and saving an actionable clickjacking proof-of-concept HTML (iframe overlay + decoy UI + adjustable opacity). No clear malware behaviors (credential theft, persistence, exfiltration, or obfuscated payloads) are present in the shown fragment, but the dual-use PoC creation significantly increases potential misuse. The fragment appears incomplete due to undefined references, so end-to-end runtime behavior may not fully match intent; however, the demonstrated PoC capability is clearly present.

Confidence: 70%Severity: 62%
Audit Metadata
Analyzed At
Aug 22, 2026, 08:09 AM
Package URL
pkg:socket/skills-sh/rifteo%2Fskills%2Fclickjacking-hunter%2F@6c38499326204e9727ac2c89a255b9cc21525eb46558f3c971f7e713566ddb9b
Security Audit — socket — clickjacking-hunter