dangling-markup-injection
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH RISK. The skill is internally consistent as an offensive exploitation playbook, but that purpose gives an AI agent concrete capabilities to steal secrets from web applications and chain further attacks. There is little supply-chain risk, but the operational security risk is high because the skill meaningfully enables web exploitation and exfiltration.
Confidence: 93%Severity: 82%
Audit Metadata