prototype-pollution-advanced

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the static command-substitution findings are documentation artifacts, but the skill is still a high-risk offensive security playbook for AI agents. It does not show credential theft or malicious exfiltration, yet its actual footprint centers on exploit development and escalation to RCE/XSS, which is disproportionate for general-purpose agent use.

Confidence: 91%Severity: 82%
AnomalyLOW
KNOWN_GADGETS.md

The provided content is exploit-focused prototype-pollution and gadget-chain guidance, including a highly suspicious example that attempts to steer Node execution via __proto__ (shell/NODE_OPTIONS/--require). This excerpt contains no runnable library logic, so it does not by itself demonstrate data theft or active compromise; however, its explicit RCE-oriented payload material is a significant red flag for the overall package and warrants inspection of the actual shipped code (especially any code that parses/merges untrusted objects, template/build manipulation, postinstall/build scripts, or child_process usage).

Confidence: 45%Severity: 45%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:15 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fprototype-pollution-advanced%2F@fd4207b10e5370b370a1ccc17fbc1125b41e48ae1168c0520d1f26c41f759893
Security Audit — socket — prototype-pollution-advanced