subdomain-takeover

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for subdomain takeover assessment and does not show credential harvesting or covert exfiltration, but it meaningfully expands an AI agent into offensive security scanning with optional exploitability verification. Supply-chain risk is moderate due to unpinned external tool installs, and overall risk is high because the capability itself can be misused against external targets.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Aug 19, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/woohyun212%2Fsecurity-skill%2Fsubdomain-takeover%2F@840e21d5b4f98f09da64f4658e7757394aeda6180355d45a25c83876c311dfd6
Security Audit — socket — subdomain-takeover