cmdi-command-injection

Fail

Audited by Socket on Sep 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS. The skill is an offensive exploitation playbook that teaches an AI agent to execute command-injection attacks, read sensitive files, exfiltrate data to attacker-controlled endpoints, and launch reverse shells. The attack capability is the skill’s actual function, making it fundamentally unsafe for agent deployment even though most dangerous strings appear as instructional content rather than auto-executing directives.

Confidence: 95%Severity: 98%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:15 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fcmdi-command-injection%2F@7f6d46917b5c7657b0049f366eabaf4cad629d7b88aff28470602884e7819bf4
Security Audit — socket — cmdi-command-injection