hunt-source-leak

Warn

Audited by Socket on Jul 31, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its purpose and capabilities are internally consistent for red-team recon, but that purpose itself grants an AI agent broad exploit-adjacent behavior: probing external systems, installing scanning tools, downloading untrusted content, reconstructing source, and extracting secrets. Not confirmed malware, but it is a dangerous skill that materially increases attack capability.

Confidence: 93%Severity: 91%
SecurityMEDIUM
references/react-api-extraction.md

This code is a reconnaissance/extraction workflow that fetches React source maps and parses embedded sourcesContent to enumerate API endpoints and hunt for secret-like strings, then outputs the findings for downstream testing/exploitation. No direct malware execution or network exfiltration is present in the shown fragment, but it meaningfully facilitates sensitive information discovery and increases attacker capability; therefore it represents a high security risk if included in a supply chain or executed against targets without authorization.

Confidence: 78%Severity: 80%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:53 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-source-leak%2F@b99fb807ba19e808dcf16f6f7e26139bfdfa17fd9e1ca9cf65f9fb378d434562
Security Audit — socket — hunt-source-leak