web2-recon

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a bug-bounty/web recon guide, but its actual footprint is a high-risk offensive security capability for an AI agent. There is no clear credential exfiltration or malware behavior, yet the combination of autonomous scanning, secret/source extraction, and multiple third-party tool chains makes it unsafe and disproportionate for general agent use.

Confidence: 93%Severity: 84%
Audit Metadata
Analyzed At
Aug 6, 2026, 05:52 PM
Package URL
pkg:socket/skills-sh/shuvonsec%2Fclaude-bug-bounty%2Fweb2-recon%2F@03428aced1109489b02fbdb1b4108691f1a668b875762611e692dcdf933a25ce
Security Audit — socket — web2-recon