dependency-confusion
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its purpose is coherent, but that purpose is to equip an AI agent with offensive dependency-confusion capabilities, including recon, package publication strategy, and install-hook callback PoCs. No hidden credential theft or deceptive data routing is evident, yet the exploit focus, external callback guidance, and cross-skill routing make it inappropriate for general use and high risk if enabled.
Confidence: 92%Severity: 83%
Audit Metadata