hunt-nodejs

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a red-team Node.js hunting guide, but it equips an AI agent with active exploitation, exfiltration testing, and OOB callback workflows. Supply-chain risk is low, but the offensive security and data-exfiltration footprint make the skill high risk overall.

Confidence: 95%Severity: 91%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-nodejs%2F@c7fd22d4c70ee9ec2ed056dda41c181e77b18f470aab151a4262e92216e3efe6
Security Audit — socket — hunt-nodejs