patch-diff-exploit

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

High-risk offensive exploit-development skill. Its stated purpose and actual capabilities are aligned, but that purpose is to turn patches into usable attacks and hand them off for weaponization. External tool use is partly legitimate, yet the bootstrap includes an unverifiable offensive proxy tool and immediate-action directives, making the skill dangerous even without evidence of credential theft or covert exfiltration.

Confidence: 95%Severity: 94%
Audit Metadata
Analyzed At
Aug 2, 2026, 12:45 PM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill-private%2Fpatch-diff-exploit%2F@7fa538f8b4b05679ea8212bb46b27a5898618b15f3a1cb6e0a91938a543263aa
Security Audit — socket — patch-diff-exploit