csp-bypass-advanced

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an offensive security guide, but its stated purpose is to bypass CSP and exfiltrate data, which gives an AI agent explicit exploit-enablement capabilities. There is no installer, no credential harvesting path, and no hidden data flow in the skill itself, so this is not confirmed malware; however, as an AI Agent Skill it meaningfully increases offensive operational risk.

Confidence: 94%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fcsp-bypass-advanced%2F@a113d25de45bf6e707a3e0a4561a1ab7020c0f76be108d7b20616327bef89135
Security Audit — socket — csp-bypass-advanced