exploitation-knowledge

Fail

Audited by Socket on Aug 7, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH RISK. The skill is purpose-built to help an AI agent perform offensive exploitation against remote targets, including RCE, shell acquisition, brute force, and post-compromise file access. Its raw-GitHub PoC download guidance adds supply-chain risk, but the main issue is that the capability itself is an AI-agent exploitation toolkit, not a narrowly scoped benign integration.

Confidence: 95%Severity: 93%
MalwareHIGH
skill-report.json

This Markdown skill/playbook contains highly actionable offensive exploitation instructions rather than defensive or safe educational material. It includes multiple reverse-shell payload variants (bash/Python/PHP/netcat/named pipes), web-shell command-execution workflows, credential abuse tooling guidance, explicit sensitive file/flag/data capture steps (e.g., user.txt and /etc/passwd), and evasion guidance (e.g., Base64→bash and alternative execution paths). While it is not a stealthy self-contained malware binary, the distributed content meaningfully enables unauthorized compromise and data theft, making the security risk extremely high for any general-use package context.

Confidence: 90%Severity: 97%
Audit Metadata
Analyzed At
Aug 7, 2026, 07:08 PM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fexploitation-knowledge%2F@c34de12e144589c25634d3bc454e6ab23e156c6c7bb582e7d0bd85962e711532
Security Audit — socket — exploitation-knowledge