web2-recon

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an offensive web recon pipeline, but that purpose itself gives an AI agent high-risk exploit/scanning capability. The main concerns are offensive-security enablement, autonomous external probing, untrusted-content processing with exec capability, and reliance on numerous third-party tools with limited provenance detail in the skill.

Confidence: 92%Severity: 89%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:34 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fweb2-recon%2F@16f0664fad9a7eb52537d327a72939b7248fb08e153264d61bef989338651993
Security Audit — socket — web2-recon