recon-subdomain

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS from an AI-agent safety perspective: the skill is internally coherent for security reconnaissance, but it grants offensive security capabilities against external targets and includes active enumeration workflows. Install trust is mixed—official same-repo Go installs for core tools are reasonable, while optional personal-repo tools and unpinned @latest/source installs raise supply-chain risk. No clear credential theft or covert exfiltration is present, so this is high-risk offensive tooling rather than confirmed malware.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Mar 30, 2026, 07:54 AM
Package URL
pkg:socket/skills-sh/crazyMarky%2Fpentest-skills%2Frecon-subdomain%2F@a29deacf017bacf525aaa5bf65f577cfa74874d4