hunt-cloud-misconfig

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a red-team cloud misconfiguration hunter, and its install path is mostly benign, but it gives an AI agent offensive reconnaissance, credential-acquisition, validation-write, and exfiltration-capable workflows against real external systems. The main risk is not deceptive supply chain behavior; it is the explicit security/exploit capability and potential autonomous impact.

Confidence: 93%Severity: 85%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-cloud-misconfig%2F@3331b06a0a1ca633384739d28d9e5602b6ae9d4fbd9465c273694368f59418d1
Security Audit — socket — hunt-cloud-misconfig