subdomain-takeover

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent, but it equips an AI agent to perform offensive security actions with real-world impact, including subdomain claiming, NS takeover, and MX-based email interception. There is little evidence of malware or credential theft by the skill itself, yet the operational risk is high because the skill’s purpose is exploitation against external targets.

Confidence: 92%Severity: 83%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:15 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fsubdomain-takeover%2F@76401ca16a5b516405cd2f3a4561f116552a26c50b0cf1c88aac97aa27e8ef29
Security Audit — socket — subdomain-takeover