hunt-api-misconfig

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK but not confirmed malware. The skill is internally consistent with its stated purpose, but that purpose is to enable offensive API exploitation by an AI agent, including auth bypass and privilege escalation techniques. Install trust and data-flow concerns are limited, yet the capability set itself makes the skill high risk.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fhunt-api-misconfig%2F@d6254e12b4edf41de7203eb73875fcdd8d95c9a02491ee74d28c7bd309c6eea7
Security Audit — socket — hunt-api-misconfig