origin-ip-discovery

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally consistent and not obviously malware, but it is a high-risk offensive recon skill. Its purpose is to bypass CDN/WAF defenses and expose origin infrastructure, with live probing and port scanning of discovered hosts; install and credential flows appear mostly legitimate, yet the enabled capability is inappropriate for a general AI agent without strict authorization controls.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Forigin-ip-discovery%2F@d5c0423a6e857929f1b07bc4d314f3257e05c1de33a76be5f79571db67cd8cd4
Security Audit — socket — origin-ip-discovery