hunt-prototype-pollution
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a red-team prototype-pollution hunting guide, but it gives an AI agent explicit offensive exploit procedures, remote RCE payloads, and TLS-bypassing curl usage. There is no strong evidence of malware or credential theft, yet the operational security risk is high because the skill meaningfully enables exploitation against arbitrary targets.
Confidence: 90%Severity: 82%
Audit Metadata