privesccheck
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS. The stated purpose matches the capability: this is a privilege-escalation enumeration skill. However, it is high-risk because it equips an AI agent with offensive security behavior and instructs download-and-execute from an arbitrary ATTACKER-controlled HTTP host instead of the official upstream repository. No credential theft is shown, but the install/data path is inconsistent with legitimate same-org distribution and materially increases supply-chain risk.
The supplied content is offensive-security documentation, not the PrivescCheck source code. It contains a high-risk delivery pattern: unauthenticated HTTP download followed by in-memory IEX execution, which can execute arbitrary attacker-controlled PowerShell. The local examples perform privilege-escalation reconnaissance and may generate sensitive reports. No direct malware behavior is demonstrated in the provided fragment, but the remote execution pattern should not be used without authenticated HTTPS delivery, integrity verification, and controlled authorization.