upload-insecure-files

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. This skill is internally consistent as an upload-exploitation playbook, but its actual purpose is to give an AI agent offensive security capabilities against target systems, including upload-to-RCE chains and linked exploit pivots. No direct credential theft, hidden execution, or malicious installer is present, so it is not confirmed malware, but it is a high-risk offensive skill.

Confidence: 94%Severity: 86%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fupload-insecure-files%2F@ef36b04a9fdc3bd5f78ab819c4acda8f771160c340d52afdc34e45fa45266e76
Security Audit — socket — upload-insecure-files