conducting-man-in-the-middle-attack-simulation

Fail

Audited by Socket on Aug 4, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are internally aligned, but that purpose is to give an AI agent offensive MITM capabilities that intercept credentials, manipulate traffic, and alter network state. There is little supply-chain concern in the text itself, but the operational risk is high because the skill enables credential capture and active attack techniques with real-world impact.

Confidence: 95%Severity: 90%
MalwareHIGH
scripts/agent.py

This module is high risk because it implements real ARP-spoofing (active MITM positioning) using scapy.send() plus traffic sniffing to detect cleartext protocol usage. While it attempts ARP restoration afterward, the presence of an attack-capable MITM loop makes it inappropriate as a passive/benign dependency and a serious supply-chain security concern. No credentials theft, persistence, or malware payload delivery is evident in this fragment; the dominant risk is network interception/abuse capability.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
Aug 4, 2026, 08:24 PM
Package URL
pkg:socket/skills-sh/autohandai%2Fcommunity-skills%2Fconducting-man-in-the-middle-attack-simulation%2F@2205e50de6dc19ba0345460bf2e1d8d277fcc462112bec802f809f4f6dcbffb5
Security Audit — socket — conducting-man-in-the-middle-attack-simulation