intel-agent
Audited by Socket on Jul 28, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS: the skill's capabilities broadly fit its stated recon purpose, but that purpose itself is high-risk because it enables arbitrary website scraping reconnaissance through MITM interception, full-body traffic capture, and protection fingerprinting. The main concerns are broad data capture and reliance on mutable third-party tooling, not confirmed malware.
No direct malicious payloads are shown in this documentation-only fragment, but it clearly describes a high dual-use reconnaissance capability: MITM-based full-body traffic interception with HAR export, combined with stealth/anti-detection behavior and explicit handling of bot/protection mechanisms to discover API endpoints and extraction methods (including auth/header and pagination details). This creates significant privacy/compliance and abuse risk if used against systems without explicit authorization. A deeper review is needed in the actual skill and proxy-mcp integration code to confirm data handling (redaction, scope control, and file/output behavior).