hunt-cache-poison

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. It is internally consistent as a red-team cache-poisoning hunting guide and shows no clear credential theft or malicious installer behavior, but it gives an AI agent concrete offensive exploitation capability against arbitrary third-party targets, including authenticated cache deception and chaining with smuggling/XSS. High security risk, low evidence of malware.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-cache-poison%2F@9ca88f587e1b302564ab2379be9a644f324b06eefdcdae4f0893d80ea6d41cba
Security Audit — socket — hunt-cache-poison