sector-recon-methodology
Audited by Socket on Jul 31, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the skill is internally coherent as an offensive recon methodology, but that purpose itself is high risk for an AI agent because it enables sector-wide target selection, enumeration, and batch probing of real third-party domains. No clear credential theft or malicious exfiltration is present in the provided text, yet the offensive scope, external-content-driven workflows, and missing internal script details make this a high-security-risk skill rather than benign documentation.
This module is best characterized as an active reconnaissance/vulnerability probing script, not a typical library utility. It performs unauthenticated probing of WordPress endpoints (including user enumeration), tests CORS credential reflection with spoofed headers, checks XML-RPC responsiveness, and attempts to access and fingerprint sensitive resources like /.git/config and /.env using secret-pattern heuristics. There are no strong malware indicators in this fragment (no persistence/C2/exfiltration), but the functionality is operationally dangerous and could facilitate unauthorized scanning/exploitation if bundled in a supply chain dependency without clear transparency/controls.