dangling-markup-injection

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH RISK. The skill is internally consistent as an offensive exploitation playbook, but that purpose gives an AI agent concrete capabilities to steal secrets from web applications and chain further attacks. There is little supply-chain risk, but the operational security risk is high because the skill meaningfully enables web exploitation and exfiltration.

Confidence: 93%Severity: 82%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fdangling-markup-injection%2F@bd1c3c11dd001a10aa4dd509b8181db52be105ca6c1b9c6ba6b8c8e69920ddf8
Security Audit — socket — dangling-markup-injection