injection-checking

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an injection-testing router, but its stated purpose is to enable offensive security workflows for an AI agent. This file alone has minimal supply-chain, credential, and exfiltration risk, yet it materially increases agent capability for exploit-oriented tasks, so overall risk is driven by offensive-use enablement rather than hidden behavior.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:04 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Finjection-checking%2F@0a61b5d0567722c725f066d160fa9c5183d3431d