hunt-mfa-bypass

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an MFA bypass hunting guide, but its actual purpose is offensive security enablement for an AI agent. There is little supply-chain concern, yet the exploit-oriented workflows, brute-force guidance, use of sensitive auth artifacts, and chaining with other offensive skills make the overall security risk high.

Confidence: 93%Severity: 88%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:31 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fhunt-mfa-bypass%2F@eb76bb6dc7c82fa8c9632b2f3f3b740d7fe07be9b93d83996daa08443e100c52
Security Audit — socket — hunt-mfa-bypass