dependency-confusion

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill is internally coherent as a dependency-confusion red-team playbook, but it equips an AI agent with offensive supply-chain testing steps, transitive routing to another skill, third-party security tooling, and callback-based execution proofs. File/config references are mostly documentation, not direct credential theft, yet the overall capability is high risk because it enables exploit-style actions beyond passive review.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:16 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fdependency-confusion%2F@0f45f99e67f839935d749d61bf83f04ac890e6431cc020bba72e4e41ed36a672
Security Audit — socket — dependency-confusion