websocket-security

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its purpose is coherent as a WebSocket offensive-security guide, but that purpose itself gives an AI agent exploit capability against live systems, includes exfiltration PoCs, disables TLS verification in sample code, and expands into additional security-testing scope. Install sources are mostly legitimate registries/stores, so this is not confirmed malware, but it is a high-risk offensive security skill.

Confidence: 92%Severity: 84%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:05 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fwebsocket-security%2F@13e4992c6145a8622036f968a235b9053869ae69