hunt-subdomain
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a bug-bounty subdomain takeover guide, but it gives an AI agent offensive security capabilities, including recon, validation, and limited exploitation/claim steps against arbitrary targets. Install trust is mixed but not overtly malicious; the main risk is high-impact offensive use rather than credential theft or covert exfiltration.
Confidence: 89%Severity: 79%
Audit Metadata