cloud-saas-exposure

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and uses official endpoints, but its actual purpose is to give an AI agent offensive reconnaissance capability against cloud, package-registry, and Kubernetes-related attack surface. There is no clear credential-harvesting or malware behavior, yet the exploit/recon scope is high-risk for an agent skill; sample TLS-bypass flags in docs add minor concern.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Aug 7, 2026, 09:35 AM
Package URL
pkg:socket/skills-sh/elementalsouls%2FClaude-OSINT%2Fcloud-saas-exposure%2F@45548a529c180c130526a845f04fb9570472236eab3751945d4de0779842588b
Security Audit — socket — cloud-saas-exposure