prototype-pollution-advanced

Warn

Audited by Socket on Jul 21, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an advanced prototype-pollution exploitation guide, but its actual purpose is offensive security enablement for an AI agent. It contains no installer or direct credential exfiltration path, yet it materially increases attack capability, includes transitive local skill loads, and references external tooling loosely. High security risk, but not confirmed malware.

Confidence: 88%Severity: 78%
AnomalyLOW
KNOWN_GADGETS.md

The provided content is exploit-focused prototype-pollution and gadget-chain guidance, including a highly suspicious example that attempts to steer Node execution via __proto__ (shell/NODE_OPTIONS/--require). This excerpt contains no runnable library logic, so it does not by itself demonstrate data theft or active compromise; however, its explicit RCE-oriented payload material is a significant red flag for the overall package and warrants inspection of the actual shipped code (especially any code that parses/merges untrusted objects, template/build manipulation, postinstall/build scripts, or child_process usage).

Confidence: 45%Severity: 45%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fprototype-pollution-advanced%2F@fd4207b10e5370b370a1ccc17fbc1125b41e48ae1168c0520d1f26c41f759893
Security Audit — socket — prototype-pollution-advanced