injection-checking

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The scanner findings themselves are benign documentation artifacts, and there is no credential exfiltration, installer, or hidden execution in this skill. However, the skill’s real purpose is to equip an AI agent for offensive injection testing and to route into additional exploit-focused skills, which makes it a high-risk security capability even though it does not look like malware.

Confidence: 94%Severity: 74%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Finjection-checking%2F@836b7f9654e32e77db2cbd2e1035867e4912b40cf3da7d85da5c40b2ba082459
Security Audit — socket — injection-checking