osint-email

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core HIBP and DNS behavior is consistent with an email OSINT skill, but the optional holehe installation/execution expands scope through a separate third-party reconnaissance tool and increases supply-chain and privacy risk. Data flows are mostly proportionate and go to expected endpoints, yet the skill is still risky because it automates social-account enumeration for recon purposes.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
Aug 19, 2026, 06:16 AM
Package URL
pkg:socket/skills-sh/woohyun212%2Fsecurity-skill%2Fosint-email%2F@712da8c8490df5fa6cad565304a25cc21a53a5c9
Security Audit — socket — osint-email