cloud-iam-deep

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its footprint is internally consistent with an offensive red-team purpose, but that purpose itself gives an AI agent concrete cloud exploitation, credential abuse, metadata-token harvesting, and privilege-escalation capabilities. No obvious third-party credential-harvesting proxy is present, but the offensive scope and disabled TLS examples make it unsafe to trust in normal environments.

Confidence: 96%Severity: 94%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:34 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fcloud-iam-deep%2F@dd00713bfa41ca752a662f0fea9241b192f8f4322b737b51b79b7d796fcaa91f
Security Audit — socket — cloud-iam-deep