sublist3r
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent as a Sublist3r wrapper, and its installs are standard enough, but it equips an AI agent with offensive reconnaissance capability against arbitrary external targets. Publisher/license mismatches and the added third-party `dnsx` step raise trust concerns, though there is no clear credential theft or exfiltration behavior in the provided text.
Confidence: 89%Severity: 76%
Audit Metadata