web2-recon

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is coherent with its stated purpose, but that purpose is high-risk: it equips an AI agent with offensive reconnaissance and active security scanning workflows against external targets. No clear credential-harvesting or covert exfiltration is present, yet the combination of active probing, secret discovery, cron-based monitoring, and related offensive skill chaining makes it a high-risk security skill rather than benign developer guidance.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Aug 24, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/elementalsouls%2Fclaude-bughunter%2Fweb2-recon%2F@1330f9a45c6c464dcb2fa91fa8934381507ef13c4ab83e3de01b6edfbc7248be
Security Audit — socket — web2-recon