red-team-ops
Audited by Socket on Apr 11, 2026
2 alerts found:
Securityx2No hidden or obfuscated malicious code is present in this fragment because it is an instructional guide. However, it is a highly actionable intrusion-and-compromise workflow: it teaches exploitation, reverse-shell handling, credential harvesting, screenshot/keylogging, persistence, pivoting, payload generation, and AV-evasion/encoding. Additionally, the installation instructions include a download-and-execute pattern for a remote script without integrity checks, creating a plausible supply-chain execution risk if the downloaded artifact is compromised. Overall, treat this artifact as high dual-use/misuse risk and apply strict distribution controls; review the referenced installer mechanism for integrity verification.
This skill is purpose-consistent and not overtly malicious in packaging or data flow, but it is a high-risk offensive-security reference for an AI agent. The main concern is enablement of exploit and post-exploitation activity, partially mitigated by read-only tool permissions and lack of execution/install behavior in the provided content.