intel-agent

Warn

Audited by Socket on Jul 28, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities broadly fit its stated recon purpose, but that purpose itself is high-risk because it enables arbitrary website scraping reconnaissance through MITM interception, full-body traffic capture, and protection fingerprinting. The main concerns are broad data capture and reliance on mutable third-party tooling, not confirmed malware.

Confidence: 84%Severity: 68%
SecurityMEDIUM
README.md

No direct malicious payloads are shown in this documentation-only fragment, but it clearly describes a high dual-use reconnaissance capability: MITM-based full-body traffic interception with HAR export, combined with stealth/anti-detection behavior and explicit handling of bot/protection mechanisms to discover API endpoints and extraction methods (including auth/header and pagination details). This creates significant privacy/compliance and abuse risk if used against systems without explicit authorization. A deeper review is needed in the actual skill and proxy-mcp integration code to confirm data handling (redaction, scope control, and file/output behavior).

Confidence: 62%Severity: 79%
Audit Metadata
Analyzed At
Jul 28, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/yfe404%2Fintel-agent%2Fintel-agent%2F@e791a35dcffdf2da2e20db6c7ec5f473aaeb69f7
Security Audit — socket — intel-agent