hunt-k8s

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a red-team Kubernetes exploitation guide, but its actual footprint is intentionally offensive and enables cluster compromise, secret extraction, host escape, and OOB validation against live targets. Install trust is not the main issue; the primary risk is giving an AI agent actionable penetration-testing capability with real-world impact.

Confidence: 94%Severity: 95%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-k8s%2F@677f15e167e907a7db09c50e683a0cead1096cd869527021a4945a6e46b57444
Security Audit — socket — hunt-k8s