hunt-subdomain

Fail

Audited by Snyk on Jun 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). These are not direct executable download links but include company subdomains, a placeholder ($subdomain), an OAuth callback and a visualstudio feeds host — classic subdomain-takeover / redirect vectors (and documented in the linked writeups) that can be claimed to host malware or phishing content, so they are suspicious for distribution risk.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This document is an offensive how‑to that directly instructs how to discover and claim dangling subdomains and chain takeovers into OAuth auth‑code theft, session hijacking, CSP/CORS abuse, and email spoofing — enabling deliberate malicious exploitation.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 13, 2026, 04:06 PM
Issues
2
Security Audit — snyk — hunt-subdomain