security-bounty-hunter

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and does not show credential theft, malicious data routing, or supply-chain abuse, but it explicitly equips an AI agent to perform offensive vulnerability hunting and exploitability assessment on repositories. That offensive-security purpose makes the skill high risk even though the implementation footprint shown here is otherwise restrained.

Confidence: 93%Severity: 76%
Audit Metadata
Analyzed At
Sep 12, 2026, 03:40 PM
Package URL
pkg:socket/skills-sh/eugene-ee%2Faffaan-m-ecc%2Fsecurity-bounty-hunter%2F@2b51ad4344fa2b68e14e814e20ff8fb40964e69959829df9eacc955b639599f3
Security Audit — socket — security-bounty-hunter