vhost-enumeration

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent for virtual-host discovery and shows no credential theft or covert exfiltration, but it gives an AI agent active offensive reconnaissance capabilities against arbitrary targets. Supply-chain risk is limited because the skill does not install anything itself, yet the overall security risk is high due to the penetration-testing nature and command/network access required.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fvhost-enumeration%2F@b591971b2e7c0710b77a93a51a31eee7cd4e1f136519747f5feb3e4d5216ecd5
Security Audit — socket — vhost-enumeration