cloud-security-technique

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities are internally consistent with its stated purpose, but that purpose is to enable offensive cloud exploitation by an AI agent, including privilege escalation, secret access, metadata credential harvesting, and remote command execution. No strong evidence of hidden malware or deceptive third-party routing, yet the skill materially increases attack capability and should be treated as a high-risk offensive security skill rather than benign documentation.

Confidence: 91%Severity: 82%
MalwareHIGH
references/container-escape.md

This fragment is an explicitly actionable container/Kubernetes escape exploitation playbook, including concrete commands for privilege escalation and command execution via multiple common breakout vectors (cgroup release_agent, Docker socket breakout, hostPath/chroot, kubelet `:10250` abuse, Kubernetes API pivot using service account tokens, and cloud metadata credential harvesting). Even though it is framed as authorized testing, it is directly usable for malicious takeover, so it is a high security risk artifact if shipped as a dependency or automation component. No obfuscation is evident; the danger stems from direct exploit instructions.

Confidence: 75%Severity: 85%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fcloud-security-technique%2F@891d1ae227976e05a17a6cfe2eb52b5236e329dbcb5254c357455c20f952f9b2
Security Audit — socket — cloud-security-technique