hunt-prototype-pollution

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a red-team prototype-pollution hunting guide, but it gives an AI agent explicit offensive exploit procedures, remote RCE payloads, and TLS-bypassing curl usage. There is no strong evidence of malware or credential theft, yet the operational security risk is high because the skill meaningfully enables exploitation against arbitrary targets.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-prototype-pollution%2F@844c3364a3f73c2af3115beda76229934dc3273796aaf8fc0e2e449279776ff2
Security Audit — socket — hunt-prototype-pollution