bb-methodology
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as a red-team/bug-bounty methodology, but it gives an AI agent broad offensive security capabilities, encourages autonomous live-target testing, processes untrusted external content, and routes into additional skills. There is little evidence of covert credential theft or malware, but the operational risk is high by design.
Confidence: 89%Severity: 84%
Audit Metadata