vapt

Fail

Audited by Socket on Jul 2, 2026

3 alerts found:

Securityx2Malware
SecurityMEDIUM
SKILL.md
MalwareHIGH
references/exploitation-chaining.md

High-risk offensive exploitation content. The fragment provides actionable step-by-step attack chains spanning web exploitation, AD/SMB/LDAP attacks, SQLi→OS command execution patterns, XSS→account takeover, API IDOR→privilege escalation attempts, SSH brute force, and includes a custom reverse-shell command generator plus response-based verification logic. If included in a software package/dependency, it would be a severe supply-chain security concern due to ready-to-use malicious functionality. Confidence is high that the provided content is malicious, but overall “package behavior” (e.g., whether it executes automatically on install/import) is not provable from this snippet alone.

Confidence: 86%Severity: 98%
SecurityMEDIUM
references/metasploit-reference.md
Audit Metadata
Analyzed At
Jul 2, 2026, 07:13 PM
Package URL
pkg:socket/skills-sh/DrOlu%2Fagent-skills%2Fvapt%2F@b6df2b438b1ec0a9dcb5a8fb360201164defe5b00ed932d38965dde5001a8e31
Security Audit — socket — vapt