ssh-tunneling

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent and not obviously a credential stealer, but its stated purpose is to help an AI agent conduct offensive SSH pivoting, subnet routing, scanning support, and reverse-shell enablement on compromised hosts. No suspicious third-party data routing or installer chain is present; the main risk is that the capability itself is a high-risk security/attack workflow for an autonomous agent.

Confidence: 93%Severity: 78%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fssh-tunneling%2F@268068b7aa23b44b9ae7de381c8d08684dc0d2fd75c525491ee148876d7e052f
Security Audit — socket — ssh-tunneling