conducting-man-in-the-middle-attack-simulation
Audited by Socket on Aug 4, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: The skill’s purpose and capabilities are internally aligned, but that purpose is to give an AI agent offensive MITM capabilities that intercept credentials, manipulate traffic, and alter network state. There is little supply-chain concern in the text itself, but the operational risk is high because the skill enables credential capture and active attack techniques with real-world impact.
This module is high risk because it implements real ARP-spoofing (active MITM positioning) using scapy.send() plus traffic sniffing to detect cleartext protocol usage. While it attempts ARP restoration afterward, the presence of an attack-capable MITM loop makes it inappropriate as a passive/benign dependency and a serious supply-chain security concern. No credentials theft, persistence, or malware payload delivery is evident in this fragment; the dominant risk is network interception/abuse capability.