hunt-source-leak
Audited by Socket on Jul 31, 2026
2 alerts found:
Securityx2High-risk offensive security skill. Its purpose and capabilities are internally consistent for red-team recon, but that purpose itself grants an AI agent broad exploit-adjacent behavior: probing external systems, installing scanning tools, downloading untrusted content, reconstructing source, and extracting secrets. Not confirmed malware, but it is a dangerous skill that materially increases attack capability.
This code is a reconnaissance/extraction workflow that fetches React source maps and parses embedded sourcesContent to enumerate API endpoints and hunt for secret-like strings, then outputs the findings for downstream testing/exploitation. No direct malware execution or network exfiltration is present in the shown fragment, but it meaningfully facilitates sensitive information discovery and increases attacker capability; therefore it represents a high security risk if included in a supply chain or executed against targets without authorization.