gitlab-public-recon

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities are internally aligned with its stated purpose, but that purpose is offensive secret-hunting against external GitLab targets. There is little evidence of user-credential theft or deceptive third-party routing, so this is not confirmed malware; however, it materially increases risk by enabling autonomous recon, source-code harvesting, and secret extraction.

Confidence: 92%Severity: 82%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fgitlab-public-recon%2F@ea0bf17f618fee182269af690438044962039d839de8a538480b06548e463006
Security Audit — socket — gitlab-public-recon