hunt-springboot
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent with a red-team Spring Boot hunting purpose, but it gives an AI agent concrete offensive security capabilities: credential extraction, RCE payloads, service shutdown, webshell writing, and OOB callbacks to a third-party collaborator host. Supply-chain risk is low, but overall operational risk is high because the skill is an exploit playbook for live targets.
Confidence: 97%Severity: 94%
Audit Metadata