netcat
Audited by Socket on Sep 5, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: the skill is internally consistent as a netcat guide, but its actual purpose is offensive security enablement for an AI agent. With reverse shells, bind shells, arbitrary file transfer, scanning, and command execution over network sockets, it presents high operational risk despite lacking malware, credential theft, or supply-chain abuse.
This fragment is explicitly reverse-shell/backdoor tooling. It establishes attacker-controlled network connections, spawns interactive system shells with their stdio bound to the TCP stream, and in some variants executes attacker-provided code (PowerShell IEX) or downloads and runs remote payloads on Windows. If present inside an npm/dependency or distributed artifact, it represents a critical compromise/backdoor risk rather than legitimate functionality.