recon-fingerprint

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for web fingerprinting and uses mostly legitimate same-org or registry-backed tools, so it does not look like credential theft or malware. However, it gives an AI agent active reconnaissance and scanning capabilities against external hosts, with unpinned external tool installs and some local result persistence, making it a high-risk security skill even though its data flows are otherwise proportionate.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 30, 2026, 07:53 AM
Package URL
pkg:socket/skills-sh/crazyMarky%2Fpentest-skills%2Frecon-fingerprint%2F@577df90dc2ee2ff9939d88b50ebb14000389e893