jndi-injection
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent, but its purpose is an offensive exploitation playbook for JNDI/Log4Shell. No hidden credential harvesting or deceptive install path is shown, yet it provides actionable exploit payloads, exfiltration patterns, and tooling instructions that create high misuse risk for an AI agent.
Confidence: 91%Severity: 76%
Audit Metadata