hunt-springboot

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with offensive Spring Boot exploitation, but that purpose gives an AI agent high-risk attack capabilities. Main risks are exploit execution, credential extraction from heap dumps/env, and arbitrary callback-based data flow to third-party hosts; install provenance itself is mostly benign.

Confidence: 95%Severity: 94%
Audit Metadata
Analyzed At
Aug 24, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/elementalsouls%2Fclaude-bughunter%2Fhunt-springboot%2F@f8686a5b4cf50ea52c6ebc788445c321a4c455ce8aa78f59e0049e7cbf4863f4
Security Audit — socket — hunt-springboot