bugbounty-reporter

Warn

Audited by Socket on Jul 11, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
references/disclosed-patterns/cache-poison.md

No dependency/library code was provided. The artifact is an actionable offensive cache-poisoning exploitation playbook with concrete payload patterns and cross-client validation steps, indicating malicious intent and enabling misuse. From a software supply-chain malware perspective, there is no executable behavior to analyze; from a security-risk perspective, distributing or bundling this content is concerning because it directly facilitates attacking shared caching layers and delivering poisoned responses to other users.

Confidence: 90%Severity: 85%
AnomalyLOW
references/disclosed-patterns/http-smuggling.md

No executable or supply-chain relevant malicious behavior is present in the provided fragment; it is an offensive security research/attack-instructions write-up. The primary risk is that the document contains actionable HTTP request smuggling payloads and operational guidance that could facilitate real-world exploitation against vulnerable systems. Additional review of actual packaged source/install scripts would be required to assess malware risk in a true dependency context.

Confidence: 86%Severity: 65%
Audit Metadata
Analyzed At
Jul 11, 2026, 02:54 PM
Package URL
pkg:socket/skills-sh/Rifteo%2Fskills%2Fbugbounty-reporter%2F@3f1b014e041d1a6ff01bf35bcae58a4567aaabbd920b24c197e06aaefb5c991b
Security Audit — socket — bugbounty-reporter