password-spray-methodology

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a red-team password spraying methodology, but its actual footprint is a high-risk offensive credential-attack guide for AI agents. It enables enumeration, authentication attacks, account validation, and chaining into post-compromise actions across many services; this is not confirmed malware, but it is dangerous and should be treated as a high-risk offensive-security skill.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:53 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fpassword-spray-methodology%2F@550036f1558785e144fbfe5695be3404ec025e470313ea55df710935a457e876
Security Audit — socket — password-spray-methodology