supply-chain-attack-recon
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent with a red-team supply-chain recon purpose, but that purpose itself gives an AI agent high-risk offensive security capability. There is no clear credential-harvesting or hidden exfiltration path, and most referenced tools appear official, but the skill meaningfully enables reconnaissance for dependency confusion, workflow injection, and container-secret discovery against external targets.
Confidence: 89%Severity: 86%
Audit Metadata