mcpwn

Fail

Audited by Socket on Sep 5, 2026

3 alerts found:

SecurityMalwarex2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally aligned with offensive security and debugging, but its footprint is inherently high risk: sudo-capable command execution, tunnels, shells, remote file transfer, and transcript preservation of sensitive findings. The biggest concern is trust: the MCPwn/NeuroMatrix ecosystem described here is not publicly verifiable from official same-org sources, so users are asked to rely on an opaque security-tool runtime with broad execution and data-movement powers.

Confidence: 84%Severity: 82%
MalwareHIGH
references/tunnels-and-shells.md

The fragment is overtly intrusion-oriented and describes complete capabilities for establishing C2 reachability (VPN/expose/forward), performing SOCKS pivoting (chisel/ssh + proxychains), receiving reverse shells (penelope/nc with PTY handling), delivering staged payloads, and maintaining persistence via systemd-run—plus Windows/AD/Kerberos post-exploitation workflows and firewall weakening guidance. Even without code-level verification of hidden behavior, the described operational actions are high-impact and consistent with malware/backdoor tooling. Treat the containing package as extremely high risk and subject it to deep static/dynamic analysis for any embedded executables, payload loaders, or runtime networking/credential-handling logic.

Confidence: 68%Severity: 95%
MalwareHIGH
references/files-and-artifacts.md

The fragment describes an end-to-end agent workflow that (a) downloads artifacts over an HTTP CAS data plane and (b) stages and uploads a curated set of offensive/credential-theft and post-exploitation tools to remote hosts via SMB/other protocols, including explicit pass-the-hash authentication and remote path placement suitable for execution. This is highly indicative of intrusion-enabling capability rather than benign analysis-only functionality. While the exact implementation details are not fully visible, the operational content and explicit abuse mechanisms (credential dumping tooling + pass-the-hash + remote staging) make the security risk extremely high in a supply-chain context.

Confidence: 74%Severity: 95%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fmcpwn%2F@71e053708666b22ee5a95569cc5550eeddcad9f2fcff392c0a1632b0b4bc4257
Security Audit — socket — mcpwn