llm-prompt-injection

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an authorized LLM red-team guide and uses standard dependencies with no obvious credential theft or malicious supply chain. However, it is an offensive security skill that teaches prompt/system-prompt extraction and indirect injection techniques against live targets, so its operational risk is high even without confirmed malware behavior.

Confidence: 93%Severity: 76%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fllm-prompt-injection%2F@56ccf799efc92bc7be06c9ad5d80deeed58a5d9cf2de77affddb5b1bdadbce72
Security Audit — socket — llm-prompt-injection