pwncat
Audited by Socket on Sep 5, 2026
3 alerts found:
Securityx3SUSPICIOUS/HIGH-RISK skill. The content is internally consistent with its stated purpose, but that purpose is offensive post-exploitation: it enables reverse shells, privilege escalation, persistence implants, file transfer, and reconnect workflows on target systems. Install trust for pwncat-cs appears consistent with the official project and PyPI, so the main concern is not supply-chain deception but that this skill equips an AI agent with penetration-testing and persistence capabilities with real-world impact.
No executable malware is present in the fragment itself; it is a plain-text post-exploitation playbook. However, it explicitly provides actionable steps for privilege escalation and persistence (authorized key injection and PAM/passwd persistence as fallback), plus reconnection and cleanup flows. In a supply-chain context, distributing such content materially increases misuse risk even without hidden/obfuscated execution.
No executable malicious code is present in the fragment because it is documentation containing actionable reverse/bind shell and implant/persistence guidance. However, it includes a concrete /dev/tcp reverse-shell payload, network listener/callback orchestration, SSL options, and OPSEC evasion and reconnect/implant lifecycle instructions—making it a high-misuse-risk artifact if packaged or distributed as a dependency within a software ecosystem.