recon-technique

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: this is not credential-stealing malware, but it is a high-risk offensive security skill. Its capabilities are aligned with its stated recon purpose, yet that purpose gives an AI agent autonomous network-enumeration and target-profiling workflows that can materially affect real systems; install trust is mixed but mostly from legitimate upstream tools, and there is no clear hidden exfiltration beyond normal recon outputs.

Confidence: 91%Severity: 79%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Frecon-technique%2F@1061aacbb2c9d57a84c430039b31ab41357ca2825484a64996c9de32a0fb5abb
Security Audit — socket — recon-technique