bb-methodology

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a red-team/bug-bounty methodology, but it gives an AI agent broad offensive security capabilities, encourages autonomous live-target testing, processes untrusted external content, and routes into additional skills. There is little evidence of covert credential theft or malware, but the operational risk is high by design.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:52 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fbb-methodology%2F@1b3b4328d3991cc4e363ed19900ef5b72398d7d5e68ea3117590982e3a9af4bd
Security Audit — socket — bb-methodology