expression-language-injection
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: no installer, credential theft path, or hidden exfiltration is present, so this is not confirmed malware; however, the skill is an offensive exploit guide that enables command execution against target applications and includes stealth-oriented cleanup. Its footprint is coherent with its stated purpose, but that purpose itself gives an AI agent dangerous real-world attack capability, making overall security risk high.
Confidence: 95%Severity: 86%
Audit Metadata