hunt-lfi

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's footprint is coherent with its stated purpose, but that purpose is to equip an AI agent with active offensive exploitation capabilities against external targets. It includes OOB exfiltration workflows, sensitive-file access, RCE techniques, and execution of an unpinned third-party helper, so it should be treated as high risk even without clear malware or concealment.

Confidence: 94%Severity: 84%
Audit Metadata
Analyzed At
Aug 24, 2026, 11:06 PM
Package URL
pkg:socket/skills-sh/elementalsouls%2Fclaude-bughunter%2Fhunt-lfi%2F@754f3034618d232c214d4bd246c59abaad0a835fca08edb4ef7d75f06828d46c
Security Audit — socket — hunt-lfi