subdomain-takeover

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该 skill 的 stated purpose 与实际内容一致,但它是一套面向 AI 代理的进攻性子域名接管/利用指南,而非单纯审计参考。最大风险来自 offensive capability 本身,以及将云凭据转发给第三方开源扫描器(尤其 dnsReaper)的做法。整体应判定为高风险、可疑而非确认恶意。

Confidence: 93%Severity: 89%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:11 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fsubdomain-takeover%2F@c6ad88722db4f7ea7a3d02c7c7b5bcdc3f95b100