type-juggling

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent and documentation-only, but its stated purpose is to equip an AI agent with offensive techniques to bypass PHP authentication, token, and HMAC checks. There is no malware behavior, credential theft, installer risk, or hidden data flow; the main risk is that this security/exploit capability does not belong in a general-purpose agent without careful restriction.

Confidence: 94%Severity: 74%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Ftype-juggling%2F@5b4d74543fdaf4a574b14aa3eb5c26488b391815f8a9f8a2c784f15e42ab92f2
Security Audit — socket — type-juggling