hunt-file-upload

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a file-upload bug-hunting guide, but its actual function is to equip an AI agent with offensive exploit techniques against live targets. There are no installer or credential-routing red flags in the provided text, yet the exploit capability itself makes this a high-risk security skill.

Confidence: 92%Severity: 82%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fhunt-file-upload%2F@dbc4f6b51f9a2e932978a72dbe30bf41c5bffcf36ebe08f79af7b296c2076f16
Security Audit — socket — hunt-file-upload