bugbounty-ideas

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally coherent and not malicious: it reads a local README and public sources to produce bug bounty ideas, with explicit scope and safety boundaries. However, it still equips an AI agent with offensive-security research capability, so it should be classified as suspicious/high-risk rather than benign despite the absence of credential theft, installers, or covert data flows.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:15 PM
Package URL
pkg:socket/skills-sh/0xyon3%2Fdotfiles%2Fbugbounty-ideas%2F@eecb19e78d80267db4dbf99a683cbe3a747162ac3faf189eeaec377efa797629
Security Audit — socket — bugbounty-ideas