collecting-open-source-intelligence

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally coherent for OSINT/threat-intelligence work and routes data to mostly official services, so it does not look like credential theft or malware. However, it equips an AI agent with offensive-security reconnaissance capabilities and processes large amounts of untrusted external content, making it high risk as an agent skill even without clearly malicious intent.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:22 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fcollecting-open-source-intelligence%2F@fdc2f7e0929fc9ed6602c95e8f28677d66561d23