type-juggling
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent and documentation-only, but its stated purpose is to equip an AI agent with offensive techniques to bypass PHP authentication, token, and HMAC checks. There is no malware behavior, credential theft, installer risk, or hidden data flow; the main risk is that this security/exploit capability does not belong in a general-purpose agent without careful restriction.
Confidence: 94%Severity: 74%
Audit Metadata