recon-github-code-leaks

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities are internally consistent with its stated purpose, but the purpose itself is offensive secret-hunting and foothold discovery against third-party organizations. Data flows mostly stay on official platforms and AWS, with no clear credential harvesting proxy or covert exfiltration, so this is not confirmed malware; however, enabling an AI agent to scan public code history for secrets and test found credentials creates high misuse risk.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Frecon-github-code-leaks%2F@e0fb0277752ebc2ccc0a1a1f1d742f77b94e9d78e79bf3cac93a37c00ccafa62
Security Audit — socket — recon-github-code-leaks