unauth-api-flow-hijack

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its footprint is coherent with its stated purpose, but that purpose is to equip an AI agent with offensive exploitation steps against unauthenticated APIs, including upload, export, replay, and cross-session enumeration. No strong malware or supply-chain evidence appears, but the offensive capability, arbitrary external targeting, file transfer behavior, and disabled TLS checks make it high risk.

Confidence: 96%Severity: 88%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Funauth-api-flow-hijack%2F@32e924c73f8fc31147b4548f4ce78eca45c712819e359fa2ce9a056cdb3f1499
Security Audit — socket — unauth-api-flow-hijack