ssti-server-side-template-injection

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: this skill is a coherent but explicitly offensive exploit playbook for AI agents, centered on SSTI-to-RCE, secret access, and OOB exfiltration. There is no installer or obvious supply-chain abuse, but the skill enables high-impact real-world attacks that are disproportionate for general agent use and should be treated as high security risk, though not confirmed malware.

Confidence: 95%Severity: 90%
SecurityMEDIUM
SCENARIOS.md

The provided file is not executable malware and contains no runtime logic, I/O, or process/network/file operations within the artifact itself. However, it is highly actionable exploitation guidance (SSTI/EL/OGNL/RCE and webshell-deployment recipes, including blind/OOB techniques) aimed at real-world targets. In a supply-chain context, the primary concern is misuse/weaponization and policy/compliance risk rather than proven malicious code execution in this specific snippet. Additional repository files would be required to assess whether any package scripts or runtime components are malicious.

Confidence: 66%Severity: 85%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fssti-server-side-template-injection%2F@68af733cce12ba1e2f481d3ceafcde002aaffe229f070b095c4ad518ba75b2df
Security Audit — socket — ssti-server-side-template-injection