hunt-graphql

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a GraphQL bug-hunting guide, and the named tools largely map to legitimate sources, but it is still a high-risk offensive security skill for AI agents because it operationalizes live exploitation techniques, authenticated abuse, and cross-API desync testing on arbitrary targets.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:33 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fhunt-graphql%2F@c03a803db726a77e53360b2a6c1abf9b201ae6b5fc22913fe2ec6fb74669519f
Security Audit — socket — hunt-graphql