prototype-pollution

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a prototype-pollution testing guide, but its core purpose is to equip an AI agent with offensive security capabilities and possible RCE chains against live targets. No strong signs of credential theft or hidden exfiltration were found, so this is high-risk offensive enablement rather than confirmed malware.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fprototype-pollution%2F@9db3fb71da8e1266828d34c221c36754240a72bf59449d664da839d6878f49b3
Security Audit — socket — prototype-pollution