red-team-ops

Warn

Audited by Socket on Apr 11, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
references/metasploit.md

No hidden or obfuscated malicious code is present in this fragment because it is an instructional guide. However, it is a highly actionable intrusion-and-compromise workflow: it teaches exploitation, reverse-shell handling, credential harvesting, screenshot/keylogging, persistence, pivoting, payload generation, and AV-evasion/encoding. Additionally, the installation instructions include a download-and-execute pattern for a remote script without integrity checks, creating a plausible supply-chain execution risk if the downloaded artifact is compromised. Overall, treat this artifact as high dual-use/misuse risk and apply strict distribution controls; review the referenced installer mechanism for integrity verification.

Confidence: 74%Severity: 70%
SecurityMEDIUM
SKILL.md

This skill is purpose-consistent and not overtly malicious in packaging or data flow, but it is a high-risk offensive-security reference for an AI agent. The main concern is enablement of exploit and post-exploitation activity, partially mitigated by read-only tool permissions and lack of execution/install behavior in the provided content.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Apr 11, 2026, 06:27 PM
Package URL
pkg:socket/skills-sh/AndrewHaward2310%2F.agents%2Fred-team-ops%2F@f1177f0b3c98c025138b9a7a52b2bbf58f15b5fe
Security Audit — socket — red-team-ops