container-technique

Fail

Audited by Socket on Sep 5, 2026

4 alerts found:

Malwarex4
MalwareHIGH
SKILL.md

This skill is a high-risk offensive exploitation guide for AI agents. Its capabilities are internally consistent with its stated purpose, but that purpose is host escape, credential abuse, and cluster compromise; treat it as a dangerous exploit skill rather than benign tooling.

Confidence: 97%Severity: 98%
MalwareHIGH
references/capability-escapes.md

This fragment contains clearly malicious exploit content: an embedded kernel module that loads successfully and triggers a bash reverse shell to an attacker-controlled endpoint, plus explicit guidance for escaping containers via high-impact capability abuse (host credential theft/modification, host process injection, and raw disk access). If this content appears in or alongside a software dependency/artifact, it represents an extreme supply-chain compromise risk and should be treated as hostile.

Confidence: 86%Severity: 100%
MalwareHIGH
references/privileged-escapes.md

This fragment is a highly malicious container-to-host escape and secret theft playbook. It provides actionable instructions to achieve host root execution by manipulating kernel/cgroup execution hooks (/proc/sys/kernel/core_pattern, /proc/sys/kernel/modprobe, cgroups release_agent) and/or by mounting and chrooting into exposed host filesystems, then exfiltrating sensitive credentials such as /etc/shadow back into the container. If found within an open-source package dependency, it would represent an extreme supply-chain risk consistent with deliberate compromise tooling.

Confidence: 90%Severity: 100%
MalwareHIGH
references/socket-and-mounts.md

The provided material is a high-confidence malicious exploitation guide for Docker/container escape. It explicitly instructs how to use Docker daemon access (docker.sock or docker-group permissions) and/or writable sensitive host bind-mounts to create privileged containers, bind-mount host root, steal credentials (e.g., /etc/shadow), and establish persistence (SSH keys, cron, sudoers/passwd). If this content appears in or accompanies a software package, it should be treated as a serious security concern requiring immediate review and mitigation. There is no obfuscation; the threat is operationally direct.

Confidence: 80%Severity: 90%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fcontainer-technique%2F@f4a266d9c82c4ec410bf6a3b2880b317d07ff32d51d9fd1e7c71abe1a3ad324e
Security Audit — socket — container-technique