worker
Audited by Socket on Jul 26, 2026
2 alerts found:
Securityx2SUSPICIOUS. The skill is internally consistent as an offensive worker-cluster guide, but that stated purpose itself is high risk for an AI agent: it enables recon, vuln scanning, exploit compilation, anonymous routing, lateral SSH access, and explicit safety-control bypass. The main issue is offensive capability and control evasion, not third-party installer trust.
This fragment is best characterized as malicious-use guidance and a ready-to-run extraction technique for evading Vercel/Next.js security controls and reconstructing protected text from initial RSC/HTML payloads. While the code itself contains no classic malware behaviors (no persistence, credential theft, or direct exfiltration in the snippet), its explicit bypass orientation and content-reconstruction pipeline create high misuse potential and should be treated as security-relevant and likely abusive in a supply-chain context.