hardcoded-credential-hunt

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities are internally consistent with its stated purpose, but that purpose is an offensive credential-hunting and auth-testing workflow for AI agents. Main risks are exploit enablement and disabled TLS verification, not malware or supply-chain abuse.

Confidence: 93%Severity: 84%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhardcoded-credential-hunt%2F@68379eb9785700f8215909c17ee1725ee3f98b16f33ac4818565c83d2c94c7b6
Security Audit — socket — hardcoded-credential-hunt