executing-red-team-exercise

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s offensive capabilities match its stated red-team purpose, so it is internally coherent, but it is still a high-risk AI-agent skill because it operationalizes phishing, stealth, credential theft, persistence, lateral movement, and exfiltration. No confirmed malware or hidden installer is present, but the real-world attack guidance and evasion content make it unsafe to enable broadly.

Confidence: 95%Severity: 94%
Audit Metadata
Analyzed At
Aug 27, 2026, 07:39 AM
Package URL
pkg:socket/skills-sh/galyarderlabs%2Fgalyarder-framework%2Fexecuting-red-team-exercise%2F@16643483bf2cbc80906cea893ad2335b24f6f846f307e77016304bdb3df0ecfe
Security Audit — socket — executing-red-team-exercise