expression-language-injection

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an EL-injection exploitation playbook, but that stated purpose is itself a high-risk offensive capability for an AI agent. There is no supply-chain or credential-harvesting behavior in the skill text, yet it meaningfully enables remote exploitation, sandbox bypass, command execution, and output exfiltration against target systems.

Confidence: 95%Severity: 92%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fexpression-language-injection%2F@d032cceccfdbad1d33de5bd4e2c35531e090a34429a96347ef728de45173cb2f
Security Audit — socket — expression-language-injection