ics-technique

Warn

Audited by Socket on Sep 5, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities align with its stated purpose as an ICS/OT assessment technique, but that purpose is itself an offensive security workflow for an AI agent with potential real-world physical impact. No clear credential harvesting or hidden exfiltration is present, and the flagged installs are mostly normal documentation examples, but the skill still enables high-consequence scanning, exploitation, writes, PLC state changes, and IT/OT pivoting; this makes overall security risk high even without confirmed malware intent.

Confidence: 92%Severity: 84%
SecurityMEDIUM
references/ics-enumeration.md

This fragment is an actionable OT/ICS reconnaissance and fingerprinting playbook that performs active network scanning (including industrial protocol discovery), sends crafted Profinet DCP-related packets via scapy, and probes historian web interfaces (with TLS verification disabled). While it does not itself constitute a malware payload (no persistence or exfiltration shown), it meaningfully enables offensive enumeration and could be used to support unauthorized access—especially given the included MSSQL credential-testing guidance. If found bundled within a software package, it would be a serious red flag for misuse; however, as provided, it is not demonstrably supply-chain injected code.

Confidence: 70%Severity: 78%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fics-technique%2F@fb6c89731f16e1cc0cd86a824c78d88498ce3828fe4689d59b4356a758012163
Security Audit — socket — ics-technique