hunt-csrf

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an offensive CSRF hunting guide, but that purpose itself gives an AI agent exploit-oriented capabilities against live targets. No malware, exfiltration service, or supply-chain abuse is evident; the main risk is enabling autonomous security testing and state-changing exploit attempts.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-csrf%2F@1a2ebf6f54ce839088f96c9d65c2518286872f8e758ca9c405f7be10e8ebdc62
Security Audit — socket — hunt-csrf