sector-recon-methodology

Warn

Audited by Socket on Jul 31, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an offensive recon methodology, but that purpose itself is high risk for an AI agent because it enables sector-wide target selection, enumeration, and batch probing of real third-party domains. No clear credential theft or malicious exfiltration is present in the provided text, yet the offensive scope, external-content-driven workflows, and missing internal script details make this a high-security-risk skill rather than benign documentation.

Confidence: 89%Severity: 81%
AnomalyLOW
scripts/parallel_sector_probe.py

This module is best characterized as an active reconnaissance/vulnerability probing script, not a typical library utility. It performs unauthenticated probing of WordPress endpoints (including user enumeration), tests CORS credential reflection with spoofed headers, checks XML-RPC responsiveness, and attempts to access and fingerprint sensitive resources like /.git/config and /.env using secret-pattern heuristics. There are no strong malware indicators in this fragment (no persistence/C2/exfiltration), but the functionality is operationally dangerous and could facilitate unauthorized scanning/exploitation if bundled in a supply chain dependency without clear transparency/controls.

Confidence: 74%Severity: 68%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fsector-recon-methodology%2F@dfb9533e3985369140990d4f81f9f4375a87342b3af2ca3c5e9151bde0eebb98
Security Audit — socket — sector-recon-methodology