browser-exploitation-v8
Audited by Socket on Jul 21, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: the skill is internally coherent, but its stated purpose is to enable browser exploitation and sandbox escape by an AI agent. Install provenance is mostly legitimate and same-org, yet the capability itself is a high-risk offensive security function and includes transitive references to additional exploit skills.
This fragment is strongly indicative of offensive V8 exploitation tooling: it provides low-level pointer/bit conversion helpers, explicit engine-intrinsic workflow for JIT/GC manipulation and introspection, and detailed guidance for heap spraying, type/map/length confusion, arbitrary read/write via ArrayBuffer backing_store corruption, and sandbox escape/execution hijack through WASM/JIT control-flow target tampering. In a supply-chain context, shipping such material is highly suspicious and represents a serious security risk.