sensitive-file-reader
Warn
Audited by Socket on Sep 9, 2026
2 alerts found:
Securityx2SecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill openly performs a real read of /etc/shadow, which is disproportionate for ordinary diagnostics and exposes credential material if executed. It is not overt malware because there is no exfiltration, stealth, or external payload, but the local sensitive-file access creates clear high security risk.
Confidence: 94%Severity: 74%
Securityget_info.py
MEDIUMSecurityMEDIUM
get_info.py
The fragment directly accesses and exposes /etc/shadow. This is a serious credential-reading behavior and should be treated as unauthorized unless clearly justified by a privileged system-administration use case. The fragment alone does not demonstrate exfiltration or malware, but it provides a capability commonly associated with credential harvesting.
Confidence: 98%Severity: 80%
Audit Metadata