privilege-escalation

Fail

Audited by Socket on Apr 11, 2026

5 alerts found:

Securityx2Malwarex3
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities are aligned with its stated purpose, but that purpose is to help an AI agent conduct privilege escalation, lateral movement, and cloud/AD attacks on real systems. No clear malware or covert exfiltration is shown in the provided text, but the operational risk is substantial.

Confidence: 91%Severity: 90%
SecurityMEDIUM
references/active-directory.md

This is a highly actionable offensive AD attack reference rather than executable code. The fragment itself does not demonstrate malware execution, persistence, or data exfiltration in-module. However, its contents materially facilitate credential theft, Kerberos ticket forging, NTLM relay/poisoning, ADCS exploitation, and multiple high-impact CVE exploitation paths if executed by an operator—making it a high security-risk asset to include in a software supply chain unless clearly justified as authorized security research/training content with appropriate controls.

Confidence: 66%Severity: 85%
MalwareHIGH
references/windows-privesc.md

This fragment is an offensive Windows post-exploitation cheat sheet that materially enables credential harvesting and privilege escalation. It provides actionable steps to enumerate targets, extract secrets from multiple sources (WiFi keys, autologin/registry secrets, PuTTY/VNC passwords, PowerShell history, cmdkey store, and sensitive hive/NTDS/SAM access guidance), and execute payloads including reverse-shell templates. No intrinsic obfuscation is evident, but the operational nature of the content makes it strongly suspicious for malicious supply-chain inclusion. Treat any dependency containing this material as high security risk and investigate provenance and usage context before trust.

Confidence: 80%Severity: 88%
MalwareHIGH
references/linux-privesc.md

This fragment is an offensive Linux privilege-escalation and post-exploitation cheat sheet. It contains direct remote script execution (`curl ... | sh`, `wget ... && ./...`), attacker-hosted payload download/compile/run, reverse shell one-liners, and multiple privilege escalation techniques (sudo GTFOBins, SUID/capabilities/cron/NFS/path hijacking). High likelihood of malicious use (or at minimum, clearly weaponized instructions).

Confidence: 45%Severity: 90%
MalwareHIGH
references/cloud-security.md

This artifact functions as an offensive, multi-cloud exploitation playbook. It provides actionable instructions for credential/token harvesting via cloud metadata/identity services, privilege escalation and persistence (IAM/Azure admin-equivalent access), serverless code injection (Lambda update), remote execution via managed tooling (SSM/VM run-command), and secret/data theft (S3 sync, Lambda env, Key Vault, EC2 volume mount). As a dependency/supply-chain component, it represents a very high security risk due to direct enablement of real compromise workflows, even though the provided snippet is documentation rather than executable code.

Confidence: 84%Severity: 92%
Audit Metadata
Analyzed At
Apr 11, 2026, 06:34 PM
Package URL
pkg:socket/skills-sh/AndrewHaward2310%2F.agents%2Fprivilege-escalation%2F@87725e81210d58729cee204d8d7b4447488ab4f1
Security Audit — socket — privilege-escalation