reverse-ssh

Fail

Audited by Socket on Sep 15, 2026

2 alerts found:

MalwareAnomaly
MalwareHIGH
SKILL.md

MALICIOUS. The skill’s purpose is fundamentally offensive: obtaining shell access from a victim to an attacker, plus pivoting and proxying. Data flows and capabilities are fully aligned with unauthorized remote access activity, and the medium supply-chain uncertainty around the binary increases risk further.

Confidence: 96%Severity: 98%
AnomalyLOW
references/deployment-and-hardening.md

The input is documentation for a dual-use reverse-SSH remote-access tool, not implementation code. It describes outbound callback connections and remote shell/SFTP/forwarding capabilities that could function as an unauthorized backdoor if deployed without consent. The hardening guidance reduces risk but does not eliminate the inherent remote-access threat. No direct malware behavior or obfuscation is demonstrated in the supplied material.

Confidence: 98%Severity: 65%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Freverse-ssh%2F@970ee52533b6417202beb2a56aca1d96370690ff6c8e2c2d5dce08896fed6f51
Security Audit — socket — reverse-ssh