hunt-springboot

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with a red-team Spring Boot hunting purpose, but it gives an AI agent concrete offensive security capabilities: credential extraction, RCE payloads, service shutdown, webshell writing, and OOB callbacks to a third-party collaborator host. Supply-chain risk is low, but overall operational risk is high because the skill is an exploit playbook for live targets.

Confidence: 97%Severity: 94%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-springboot%2F@337ec554319106a10184e83e3104a853ad6b69e48a2c7ec9048c8c9942f5b76a
Security Audit — socket — hunt-springboot