reverse-ssh
Audited by Socket on Sep 15, 2026
2 alerts found:
MalwareAnomalyMALICIOUS. The skill’s purpose is fundamentally offensive: obtaining shell access from a victim to an attacker, plus pivoting and proxying. Data flows and capabilities are fully aligned with unauthorized remote access activity, and the medium supply-chain uncertainty around the binary increases risk further.
The input is documentation for a dual-use reverse-SSH remote-access tool, not implementation code. It describes outbound callback connections and remote shell/SFTP/forwarding capabilities that could function as an unauthorized backdoor if deployed without consent. The hardening guidance reduces risk but does not eliminate the inherent remote-access threat. No direct malware behavior or obfuscation is demonstrated in the supplied material.