type-juggling

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent and does not show credential theft, covert exfiltration, or untrusted installation behavior, but its stated purpose is to help an AI agent perform exploit-oriented security testing and bypass auth/signature checks. That offensive capability makes it high security risk as an agent skill, though not confirmed malware.

Confidence: 93%Severity: 82%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Ftype-juggling%2F@5b4d74543fdaf4a574b14aa3eb5c26488b391815f8a9f8a2c784f15e42ab92f2
Security Audit — socket — type-juggling