jndi-injection

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its purpose is an offensive exploitation playbook for JNDI/Log4Shell. No hidden credential harvesting or deceptive install path is shown, yet it provides actionable exploit payloads, exfiltration patterns, and tooling instructions that create high misuse risk for an AI agent.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:16 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fjndi-injection%2F@eefe6c76c9f9c829453c7c07d788489bad9a52113ae2ec2d05c6436375a6df3c
Security Audit — socket — jndi-injection