ai-identity-security

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
references/identity-attack-techniques.md

The provided content is not a software module; it is an adversarial prompt/payload playbook targeting AI agent security. It explicitly requests credential/token/system prompt disclosure, unauthorized actions via parameter tampering, attacker-controlled remote script execution, and multi-agent identity/trust manipulation. Because no actual npm package/library code is included, confidence in a supply-chain malware assessment is limited; the fragment is nevertheless strongly malicious in intent/content.

Confidence: 42%Severity: 60%
Audit Metadata
Analyzed At
May 4, 2026, 08:19 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fai-identity-security%2F@750ad2bfdb461e861443597cc1adc94927cb8d36