hunt-write-gap

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill: its footprint matches its red-team purpose, so it is internally consistent, but that purpose is to give an AI agent offensive security capabilities that perform live unauthorized write attempts with bearer tokens. No strong malware or exfiltration indicators appear, but the skill is dangerous due to exploit-oriented automation and disabled TLS verification.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-write-gap%2F@d88086016bbbfd9348f6b84167b56551f4f93c89ded8493e0899f318278fd65e
Security Audit — socket — hunt-write-gap