recon-github-code-leaks
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's capabilities are internally consistent with its stated purpose, but the purpose itself is offensive secret-hunting and foothold discovery against third-party organizations. Data flows mostly stay on official platforms and AWS, with no clear credential harvesting proxy or covert exfiltration, so this is not confirmed malware; however, enabling an AI agent to scan public code history for secrets and test found credentials creates high misuse risk.
Confidence: 89%Severity: 72%
Audit Metadata