hunt-idor

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an IDOR hunting playbook, but it grants an AI agent offensive security capabilities against arbitrary external targets, including enumeration, introspection, and potentially destructive testing. There is little supply-chain or credential-harvesting evidence; the main risk is misuse and real-world exploitation capability.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fhunt-idor%2F@73dcacec3a2632a7f3bc37c4425626308118c7b3573bf83dcd1f49b1196378c6
Security Audit — socket — hunt-idor