privesccheck

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches the capability: this is a privilege-escalation enumeration skill. However, it is high-risk because it equips an AI agent with offensive security behavior and instructs download-and-execute from an arbitrary ATTACKER-controlled HTTP host instead of the official upstream repository. No credential theft is shown, but the install/data path is inconsistent with legitimate same-org distribution and materially increases supply-chain risk.

Confidence: 93%Severity: 90%
SecurityMEDIUM
references/ps-opsec-and-reporting.md

The supplied content is offensive-security documentation, not the PrivescCheck source code. It contains a high-risk delivery pattern: unauthenticated HTTP download followed by in-memory IEX execution, which can execute arbitrary attacker-controlled PowerShell. The local examples perform privilege-escalation reconnaissance and may generate sensitive reports. No direct malware behavior is demonstrated in the provided fragment, but the remote execution pattern should not be used without authenticated HTTPS delivery, integrity verification, and controlled authorization.

Confidence: 98%Severity: 70%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fprivesccheck%2F@e18acbae84e51fed75c704cfbf5a04570a9e55eb606b146cb89e7a91307a423a
Security Audit — socket — privesccheck