ics-technique
Audited by Socket on Sep 5, 2026
2 alerts found:
Securityx2SUSPICIOUS/HIGH-RISK skill. Its capabilities align with its stated purpose as an ICS/OT assessment technique, but that purpose is itself an offensive security workflow for an AI agent with potential real-world physical impact. No clear credential harvesting or hidden exfiltration is present, and the flagged installs are mostly normal documentation examples, but the skill still enables high-consequence scanning, exploitation, writes, PLC state changes, and IT/OT pivoting; this makes overall security risk high even without confirmed malware intent.
This fragment is an actionable OT/ICS reconnaissance and fingerprinting playbook that performs active network scanning (including industrial protocol discovery), sends crafted Profinet DCP-related packets via scapy, and probes historian web interfaces (with TLS verification disabled). While it does not itself constitute a malware payload (no persistence or exfiltration shown), it meaningfully enables offensive enumeration and could be used to support unauthorized access—especially given the included MSSQL credential-testing guidance. If found bundled within a software package, it would be a serious red flag for misuse; however, as provided, it is not demonstrably supply-chain injected code.