cors-chain-automation

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its footprint is internally consistent with its stated red-team purpose, but that purpose is itself offensive: it equips an AI agent to scan for exploitable CORS flaws, replay session cookies, generate browser exploit PoCs, and chain findings with subdomain takeover. No malicious installer or hidden payload is present, but the operational exploit focus makes it unsafe.

Confidence: 92%Severity: 84%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fcors-chain-automation%2F@d623435ddfaba876360428986322d3733e881e2d02b822504364b32b940d1b67
Security Audit — socket — cors-chain-automation