authenticating
Audited by Socket on Feb 16, 2026
1 alert found:
SecurityThis skill is an offensive testing toolkit intended for authorized penetration testing and mostly aligns with its stated purpose. However, it includes explicit instructions for bypassing 2FA, CAPTCHA, and anti-bot controls, encourages use of proxies/fingerprint manipulation, and demonstrates direct handling of email credentials and OTP extraction. These capabilities are dual-use and present a significant misuse risk if executed without strict authorization, auditing, and secrets handling safeguards. There is no evidence of hidden malware or obfuscation in the content provided, but the operational security practices (plaintext credential handling, storing OTPs/session tokens) are risky. Verdict: SUSPICIOUS — legitimate for authorized pentests but high potential for abuse; require policy, access controls, and secure secrets handling before use.