js-reverse
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent for JS reverse engineering, but it gives an AI agent high-risk offensive/browser-instrumentation capabilities and instructs transitive installation of external MCP tooling via bootstrap. No clear credential theft or covert exfiltration is shown, so this is better classified as high-risk vulnerable/suspicious rather than malware.
Confidence: 86%Severity: 81%
Audit Metadata