supply-chain-attack-recon

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with a red-team supply-chain recon purpose, but that purpose itself gives an AI agent high-risk offensive security capability. There is no clear credential-harvesting or hidden exfiltration path, and most referenced tools appear official, but the skill meaningfully enables reconnaissance for dependency confusion, workflow injection, and container-secret discovery against external targets.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:52 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fsupply-chain-attack-recon%2F@bde0c89d9b5e2f8c89de4b07be17800d21257d5a92c90e2f0a2ebb78626eecb5
Security Audit — socket — supply-chain-attack-recon