bb-methodology

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a bug bounty methodology, but its actual footprint is a high-risk offensive-security orchestrator for AI agents. The strongest concerns are exploit guidance, broad autonomous probing, session reuse across tools, and explicit use of interactsh-style callback infrastructure.

Confidence: 90%Severity: 91%
Audit Metadata
Analyzed At
Aug 6, 2026, 05:52 PM
Package URL
pkg:socket/skills-sh/shuvonsec%2Fclaude-bug-bounty%2Fbb-methodology%2F@950e5a912c38b6bff2811bc8b8c1895bd760ebd09e66e11039f928295a1f3e68
Security Audit — socket — bb-methodology