js-reverse

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent for JS reverse engineering, but it gives an AI agent high-risk offensive/browser-instrumentation capabilities and instructs transitive installation of external MCP tooling via bootstrap. No clear credential theft or covert exfiltration is shown, so this is better classified as high-risk vulnerable/suspicious rather than malware.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
Aug 19, 2026, 09:14 AM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fjs-reverse%2F@28fb7edd00281574affb4eaa793b08854c4cb58111d5f395951f7ab18f68cd61
Security Audit — socket — js-reverse