nosql-injection

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a NoSQL-injection playbook, but its actual footprint is an offensive exploitation guide for AI agents, including data extraction and remote system abuse. There is no malicious installer, credential harvesting, or hidden exfiltration path, yet the skill meaningfully increases real-world attack capability and should be treated as high security risk.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fnosql-injection%2F@32cfb0d30dc71e5cfbab665518a0bf01f8e32b6ffccb9a7f6214e1425e9a98d6
Security Audit — socket — nosql-injection