offensive-osint

Fail

Audited by Socket on Aug 25, 2026

6 alerts found:

Securityx4MalwareAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an offensive recon arsenal, but that purpose itself gives an AI agent high-risk security capabilities. Main concerns are offensive security enablement, transitive chaining into other attack skills, broad processing of untrusted external content with execution capability, and moderate third-party tooling supply-chain exposure.

Confidence: 91%Severity: 88%
SecurityMEDIUM
references/identity-fabric.md

The provided content is not a software dependency module; it is an attacker-style reconnaissance and identifier-extraction workflow. It enables collection of sensitive security-relevant identifiers (AWS account IDs, OAuth client IDs/scopes), Microsoft 365 tenant/provisioning and potential exposure indicators, and GraphQL schema/field discovery via error/suggestion probing. While it contains no evidence of executable supply-chain malware itself, the operational guidance is strongly malicious in intent and materially increases the capability for targeted intrusion and data exposure.

Confidence: 85%Severity: 85%
SecurityMEDIUM
references/secret-validators.md

This fragment is a credential-driven, multi-platform reconnaissance and token-triage playbook. It uses embedded/authenticated tokens to enumerate AWS IAM capabilities and logging/MFA posture, discover secret-relevant identifiers (AWS Secrets Manager/SSM, GitHub secrets metadata, Postman environment values), enumerate Slack private channels/users, and inventory accessible GitHub org/repo scope. It additionally includes explicit JWT attack testing steps (alg=none, RS→HS algorithm confusion, and HS256 brute-force guidance). No on-host malware/persistence is visible, but the operational intent and methods indicate malicious credential abuse and compromise preparation, resulting in an extremely high security risk if found in a dependency or distributed script.

Confidence: 86%Severity: 98%
SecurityMEDIUM
references/breach-and-credentials.md

No embedded malicious code is evidenced in this fragment (it is instructional documentation rather than a functioning dependency module with runtime compromise behavior). However, it directly enables offensive reconnaissance and targeted email list creation by combining breach/infostealer corpus queries, DNS posture inference for SSO exposure escalation, and email harvesting/pattern inference from multiple public sources and scraped content. If distributed as part of a package, treat it as high dual-use/misuse risk rather than supply-chain malware, and review intended use controls and scope.

Confidence: 74%Severity: 83%
MalwareHIGH
references/sector-discovery-mass-recon.md

This artifact is an offensive reconnaissance and vulnerability validation playbook targeting third-party WordPress installations. It explicitly instructs credentialed CORS testing using an attacker-controlled Origin (to infer cross-origin authenticated access/exfiltration potential), user enumeration via the WordPress REST API (/wp-json/wp/v2/users), XML-RPC multicall capability probing, and sensitive-file probing using content/length heuristics to reduce false positives. It also includes OPSEC-oriented parallelization and rate-limit/jitter tactics to scale scanning. No code obfuscation is present; the primary concern is the actionable attack workflow and data-extraction behavior.

Confidence: 86%Severity: 97%
AnomalyLOW
scripts/sector_mass_scan.py

This module is an active web reconnaissance/vulnerability scanning utility aimed at WordPress-related exposure (REST users detection, login indicators, CORS credential reflection testing, XML-RPC enumeration/multicall detection) and common sensitive-file disclosure patterns (e.g., /.env and /.git/config). It writes detailed recon findings to local Markdown files. There is no clear evidence of stealth/exfiltration/backdoor behavior in this fragment, but it is security-relevant and potentially harmful in unauthorized contexts. The strongest technical red flag is TLS certificate verification being disabled (CERT_NONE), which makes scanning results integrity-dependent on network trust.

Confidence: 72%Severity: 56%
Audit Metadata
Analyzed At
Aug 25, 2026, 05:00 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Foffensive-osint%2F@6cc4ef79779fb67ba8f0e7b9add3786b63f2659d7305b2565796dc0e1e80faac
Security Audit — socket — offensive-osint