hackerone

Fail

Audited by Socket on Feb 20, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The code/documentation describes a powerful automation for bug bounty workflows that, as written, enables high-risk operations: execution of arbitrary PoC scripts and large-scale active testing without enforced sandboxing, consent checks, or rate limiting. These behaviors create significant supply-chain and operational risks (possible host compromise, data exfiltration, accidental DoS against targets, and unchecked exfiltration via the /pentest skill). Treat this package as potentially dangerous in production until mitigations are implemented: mandatory sandboxed PoC execution, strict concurrency controls, enforced scope authorization, and a full audit of the /pentest agent implementation and any automated submission/upload flows.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 20, 2026, 09:27 PM
Package URL
pkg:socket/skills-sh/transilienceai%2Fcommunitytools%2Fhackerone%2F@e1071eb858cdebac0a8900b95ea5d886055af71c