subfinder

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent and uses official install sources, but it grants an AI agent offensive security reconnaissance capability and encourages expansion into active scanning workflows. This is not confirmed malware or credential harvesting, yet it is a high-risk security skill with moderate supply-chain hygiene concerns from unpinned latest installs.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:20 PM
Package URL
pkg:socket/skills-sh/TerminalSkills%2Fskills%2Fsubfinder%2F@5f97be4516ca7abf35334f8285ea7c0aa14e0a4b