cms-detection

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally consistent for CMS fingerprinting, but its stated purpose is overtly offensive recon on live targets and it equips an AI agent to prepare follow-on exploitation. No credential harvesting or suspicious third-party routing is present, yet the offensive security capability and TLS-verification bypass make it a high-risk vulnerable skill rather than confirmed malware.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fcms-detection%2F@8c4fd9e3931648fdb0beaf65204b145e53b25291c9a3fc817f6a27cf8bfd8b37
Security Audit — socket — cms-detection