osint-methodology

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is not confirmed malware, but it is a high-risk offensive capability package for AI agents. Its footprint is coherent with its stated red-team/OSINT purpose, yet that purpose itself includes recon techniques, user enumeration, WAF/origin bypass, phishing planning, breach correlation, and transitive use of other offensive skills, making the skill appropriately classified as suspicious/high-risk rather than benign.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fosint-methodology%2F@ef8c6adea32018d6e705cee3a2467169e7a7eb11740ed9f241f190e2ee23dcfb
Security Audit — socket — osint-methodology