recon-and-methodology

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a recon/offensive-security playbook, but its purpose is to equip an AI agent with asset discovery, scanning, and vulnerability-testing capabilities against targets. The flagged file/URL patterns are mostly documentation examples rather than malware behavior, yet the overall skill materially increases offensive security risk and is not a benign general developer workflow guide.

Confidence: 93%Severity: 74%
Audit Metadata
Analyzed At
Sep 15, 2026, 06:49 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Frecon-and-methodology%2F@2dd8d9074ccc416c440911d80a9eee434ff9c940563223e6941bf8730d102008
Security Audit — socket — recon-and-methodology