hunt-ato

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is internally consistent as a red-team ATO methodology, but its actual footprint is highly dangerous for an AI agent: it operationalizes credential theft, token capture, phishing, brute force, and account takeover validation against real services. No strong supply-chain abuse is present, but the offensive capability and exfiltration workflows make it high-risk and suspicious to deploy.

Confidence: 89%Severity: 92%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-ato%2F@dbe64e2ab74d3625c68b2d6363e39598cc0f94c78998187562857313c0656898
Security Audit — socket — hunt-ato