Onvifscan

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The onvifscan instructions describe a legitimate ONVIF authentication scanner with an explicit brute-force capability and an option to exercise potentially destructive endpoints. While the described functionality aligns with the stated purpose, the documentation lacks provenance for the executable, lacks authorization safeguards, and omits details about result/telemetry handling. These gaps raise supply-chain and misuse risks. Treat this tool as dangerous to use unless: (1) you verify the binary's origin and integrity, (2) you have explicit authorization for testing targets, and (3) you avoid the -a/--all destructive tests unless required and confirmed.

Confidence: 75%Severity: 70%
Audit Metadata
Analyzed At
Feb 26, 2026, 01:01 AM
Package URL
pkg:socket/skills-sh/consigcody94%2Fbounty-buddy%2Fonvifscan%2F@5c09762ad33855d615b7120a4897d07af8be8878