hunt-lfi

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its behavior matches its stated red-team purpose, so it is not deceptive, but it equips an AI agent with offensive exploit procedures, third-party OOB data flows, and execution of an unpinned external repo. Risk is driven more by exploitation capability and live-target data flow than by malware indicators.

Confidence: 92%Severity: 82%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:53 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-lfi%2F@2abe5c95f91d4da1c88fcf12a39d3b9ebb94ac1ec243269ca0fc210a18bd9d34
Security Audit — socket — hunt-lfi