subdomain-takeover
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent for subdomain takeover assessment and does not show credential harvesting or covert exfiltration, but it meaningfully expands an AI agent into offensive security scanning with optional exploitability verification. Supply-chain risk is moderate due to unpinned external tool installs, and overall risk is high because the capability itself can be misused against external targets.
Confidence: 86%Severity: 72%
Audit Metadata