expression-language-injection

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: no installer, credential theft path, or hidden exfiltration is present, so this is not confirmed malware; however, the skill is an offensive exploit guide that enables command execution against target applications and includes stealth-oriented cleanup. Its footprint is coherent with its stated purpose, but that purpose itself gives an AI agent dangerous real-world attack capability, making overall security risk high.

Confidence: 95%Severity: 86%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fexpression-language-injection%2F@d032cceccfdbad1d33de5bd4e2c35531e090a34429a96347ef728de45173cb2f
Security Audit — socket — expression-language-injection