prototype-pollution-advanced
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the static command-substitution findings are documentation artifacts, but the skill is still a high-risk offensive security playbook for AI agents. It does not show credential theft or malicious exfiltration, yet its actual footprint centers on exploit development and escalation to RCE/XSS, which is disproportionate for general-purpose agent use.
The provided content is exploit-focused prototype-pollution and gadget-chain guidance, including a highly suspicious example that attempts to steer Node execution via __proto__ (shell/NODE_OPTIONS/--require). This excerpt contains no runnable library logic, so it does not by itself demonstrate data theft or active compromise; however, its explicit RCE-oriented payload material is a significant red flag for the overall package and warrants inspection of the actual shipped code (especially any code that parses/merges untrusted objects, template/build manipulation, postinstall/build scripts, or child_process usage).