hunt-nextjs

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is coherent with its stated purpose, but the purpose itself is high risk: it equips an AI agent to conduct active security testing and exploitation of Next.js targets, including SSRF confirmation through known callback collectors. No hidden installer, credential theft flow, or malware behavior is evident, but the offensive network actions make the skill suspicious and dangerous in deployment.

Confidence: 92%Severity: 87%
Audit Metadata
Analyzed At
Aug 24, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/elementalsouls%2Fclaude-bughunter%2Fhunt-nextjs%2F@6440dc6a3661019aa0676497041ed1de23683e975deaef3bc6e466f3bd61f7dd
Security Audit — socket — hunt-nextjs