hunt-api-misconfig

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its red-team purpose and has low installer/credential risk, but it gives an AI agent high-risk offensive security capabilities against arbitrary external APIs. This is not confirmed malware, yet it materially expands attack surface and should be treated as a high-risk penetration-testing skill.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:52 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-api-misconfig%2F@290f41b77e2921a5e4d84efa81f00ff1f652a7709231a658952e8891bb9e4cea
Security Audit — socket — hunt-api-misconfig