gitlab-public-recon
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its capabilities are internally aligned with its stated purpose, but that purpose is offensive secret-hunting against external GitLab targets. There is little evidence of user-credential theft or deceptive third-party routing, so this is not confirmed malware; however, it materially increases risk by enabling autonomous recon, source-code harvesting, and secret extraction.
Confidence: 92%Severity: 82%
Audit Metadata