pwncat

Warn

Audited by Socket on Sep 5, 2026

3 alerts found:

Securityx3
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. The content is internally consistent with its stated purpose, but that purpose is offensive post-exploitation: it enables reverse shells, privilege escalation, persistence implants, file transfer, and reconnect workflows on target systems. Install trust for pwncat-cs appears consistent with the official project and PyPI, so the main concern is not supply-chain deception but that this skill equips an AI agent with penetration-testing and persistence capabilities with real-world impact.

Confidence: 93%Severity: 88%
SecurityMEDIUM
references/post-exploitation-playbook.md

No executable malware is present in the fragment itself; it is a plain-text post-exploitation playbook. However, it explicitly provides actionable steps for privilege escalation and persistence (authorized key injection and PAM/passwd persistence as fallback), plus reconnection and cleanup flows. In a supply-chain context, distributing such content materially increases misuse risk even without hidden/obfuscated execution.

Confidence: 74%Severity: 85%
SecurityMEDIUM
references/connection-modes-and-opsec.md

No executable malicious code is present in the fragment because it is documentation containing actionable reverse/bind shell and implant/persistence guidance. However, it includes a concrete /dev/tcp reverse-shell payload, network listener/callback orchestration, SSL options, and OPSEC evasion and reconnect/implant lifecycle instructions—making it a high-misuse-risk artifact if packaged or distributed as a dependency within a software ecosystem.

Confidence: 78%Severity: 78%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fpwncat%2F@d1d2d1f09ce10a1f900dc00f5d814652f7af7ea68b67a90aafd0d4dd50fca4ea
Security Audit — socket — pwncat