crlf-injection

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its purpose is to arm an AI agent with offensive exploitation techniques. There are no obvious credential-harvesting or installer-trust issues in the provided text, yet the capability itself is high risk because it enables practical attacks against external systems.

Confidence: 91%Severity: 83%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:24 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fcrlf-injection%2F@6f58fecd9e99ab30e4afa6d434ea1eb1a6a37951478b0f4c2fc66e71bbd20176
Security Audit — socket — crlf-injection