hunt-oauth

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally consistent with its stated red-team purpose, but that purpose is high risk: it equips an AI agent to perform offensive OAuth security testing and exploit validation against arbitrary targets. There is little evidence of hidden malware or credential exfiltration by the skill itself, yet its operational footprint is dangerous because it combines external-target analysis, command execution, and exploit guidance for account takeover scenarios.

Confidence: 91%Severity: 89%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-oauth%2F@45ca2e6ca799f0e47788b3a5e8a917cced2f10d69602eb186c882a0f14068968
Security Audit — socket — hunt-oauth