browser-exploitation-v8

Fail

Audited by Socket on Jul 21, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent, but its stated purpose is to enable browser exploitation and sandbox escape by an AI agent. Install provenance is mostly legitimate and same-org, yet the capability itself is a high-risk offensive security function and includes transitive references to additional exploit skills.

Confidence: 95%Severity: 91%
MalwareHIGH
V8_EXPLOITATION_PATTERNS.md

This fragment is strongly indicative of offensive V8 exploitation tooling: it provides low-level pointer/bit conversion helpers, explicit engine-intrinsic workflow for JIT/GC manipulation and introspection, and detailed guidance for heap spraying, type/map/length confusion, arbitrary read/write via ArrayBuffer backing_store corruption, and sandbox escape/execution hijack through WASM/JIT control-flow target tampering. In a supply-chain context, shipping such material is highly suspicious and represents a serious security risk.

Confidence: 86%Severity: 100%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:24 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fbrowser-exploitation-v8%2F@bdcb36fa74d520dd5e7fdb69132af1687ed0dc9be3823ec96640a97d6def776f
Security Audit — socket — browser-exploitation-v8