vuln-exploit-technique

Fail

Audited by Socket on Sep 5, 2026

3 alerts found:

Malwarex3
MalwareHIGH
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities are internally consistent with its stated offensive purpose, but that purpose is to equip an AI agent with exploit, payload-delivery, and initial-access tradecraft. Multiple payload download/execute patterns, TLS-bypass examples, transitive offensive skill loading, and autonomous exploitation guidance make it a high-risk offensive-security skill rather than benign workflow automation.

Confidence: 95%Severity: 93%
MalwareHIGH
references/framework-exploitation.md

The provided fragment is a comprehensive, actionable offensive exploitation workflow for Metasploit/Meterpreter and msfvenom. It explicitly covers scanning/brute-force, exploitation, reverse/bind payload delivery, interactive post-exploitation, credential harvesting, lateral movement, and optional persistence—capabilities strongly aligned with malware and real-world unauthorized compromise. No obfuscation is present, but the content is inherently high risk if included in a software supply-chain artifact.

Confidence: 90%Severity: 100%
MalwareHIGH
references/manual-exploit-dev.md

The provided code fragment is an offensive exploitation scaffold: it connects to a remote host, receives a banner, constructs an overflow-style payload, and transmits it directly to the target. The surrounding context emphasizes return-address/shellcode injection and reverse-shell/payload handling, making the overall intent highly malicious/weaponized. If found inside any distributed dependency, it should be treated as extreme supply-chain risk (likely containing or enabling exploitation of remote services).

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fvuln-exploit-technique%2F@8af473e4d47e428eebd9e0a8cb64b200f1fa108df43250b4845e4419113371b3
Security Audit — socket — vuln-exploit-technique