endpoint-probe

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The HTTP probing behavior is broadly aligned with the stated endpoint-discovery purpose and includes reasonable SSRF safeguards, but the MCP stdio feature materially increases risk by allowing package runners to download and execute third-party server code, then forward credentials into those processes. That combination is proportionally risky for a discovery skill and warrants elevated security concern despite not being confirmed malware.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Aug 13, 2026, 11:13 AM
Package URL
pkg:socket/skills-sh/moonlight-lupin%2Fagent-skills%2Fendpoint-probe%2F@71c53ace7d9c7616b9210916c2cfbe540ed0ffab8cfadc75566541d488aa8aaa
Security Audit — socket — endpoint-probe