supply-chain-attack-recon

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose is coherent, but the purpose itself is offensive security reconnaissance for AI agents against external targets. Install provenance is mostly acceptable and data flows are mostly to official services, so this is not confirmed malware; however, the skill materially increases an agent’s ability to discover and operationalize supply-chain attack paths, process untrusted external content, and handle potentially sensitive findings.

Confidence: 93%Severity: 84%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:33 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fsupply-chain-attack-recon%2F@2fc55ffd90e46ac4ce7857d65e4eff7876dbf81454091d3a67102ea7a6e1b1c8
Security Audit — socket — supply-chain-attack-recon