hunt-mcp-security

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities as a red-team MCP hunting guide, but the capability set is inherently dangerous for an AI agent: it teaches exploitation, disables TLS checks, uses attacker-controlled endpoints, and includes exfiltration and real-world action paths. Not confirmed malware because it does not hide behavior or auto-execute payloads at load time, but it is a high-risk offensive skill that should only run in tightly authorized testing environments.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-mcp-security%2F@b7729ce146e449b648dfde5f625f0a45b69419fc6d955b05bfcc9be8e861ad92
Security Audit — socket — hunt-mcp-security