okta-attack

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill is internally coherent as an Okta red-team playbook and mostly uses official Okta endpoints, so it is not disguised credential theft or supply-chain malware. However, it gives an AI agent explicit offensive security capabilities against real external targets, including password spraying, MFA abuse checks, and post-compromise admin enumeration, which makes it a high-risk agent skill.

Confidence: 95%Severity: 93%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:34 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fokta-attack%2F@98bf1826278c53419e7b99a958fa9c046036a4ad45b906fbc135b9db9aebd38f
Security Audit — socket — okta-attack