lockpick

Warn

Audited by Socket on Sep 21, 2026

6 alerts found:

Securityx6
SecurityMEDIUM
SKILL.md

The skill is internally consistent with its stated purpose, but that purpose is an offensive post-exploitation playbook for an AI agent. It materially enables credential access, privilege escalation, container/Kubernetes escape, and lateral movement; high security risk is driven by the offensive capability set rather than deceptive install behavior. No confirmed malware or hidden exfiltration endpoint is present in the provided content.

Confidence: 93%Severity: 84%
SecurityMEDIUM
references/linux-privesc.md

The fragment is an explicit Linux privilege-escalation and post-exploitation guide. It contains commands that can obtain root privileges, read protected files, capture network traffic, modify privileged scheduled tasks, and exploit vulnerable systems. It does not by itself demonstrate autonomous malware or package-runtime behavior because the visible content is documentation and command examples, but its intended use is clearly offensive and the operational security risk of following it is high.

Confidence: 98%Severity: 93%
SecurityMEDIUM
references/kubernetes-privesc.md

The fragment is a dual-use Kubernetes security and penetration-testing guide. It contains commands that, when run in a cloud workload or cluster, can retrieve cloud credentials, enumerate privileges, dump secrets, move laterally, or attempt container escape. It does not show automatic execution, persistence, obfuscation, or covert exfiltration, so malicious package intent is not established. Execution in production or untrusted environments presents a significant security risk.

Confidence: 96%Severity: 72%
SecurityMEDIUM
references/shells-and-pivoting.md

This is an offensive security and post-compromise operations cheat sheet. It contains numerous commands capable of creating reverse shells, enabling tunneling and pivoting, scanning internal networks, and transferring sensitive files. It is not executable code and shows no automatic malware behavior, persistence, credential harvesting implementation, or hidden payload. Use is restricted to authorized security testing; unauthorized execution would create a severe security risk.

Confidence: 99%Severity: 88%
SecurityMEDIUM
references/vpn-iac-secrets.md

The fragment is an offensive security and post-compromise credential-harvesting playbook. It contains highly dangerous instructions for discovering secrets, hijacking SSH agents, accessing cloud metadata, cracking Ansible Vaults, accessing Kubernetes credentials, and pivoting through networks. It does not itself demonstrate executable malware or automatic exfiltration, but use in an unauthorized context could directly enable credential theft and lateral movement. The broader file should be reviewed for execution wrappers, package scripts, or code that invokes these commands.

Confidence: 98%Severity: 90%
SecurityMEDIUM
references/container-breakout.md

This fragment is offensive security and container-escape guidance. It includes commands that can read sensitive host files, modify /host/etc/passwd to create a root account, enter host namespaces, and execute an unverified remote script. It is not evidence by itself of npm malware or autonomous malicious behavior, but executing the commands in a privileged or misconfigured environment can compromise the host. Assessment is limited because the surrounding file and call sites are not shown.

Confidence: 96%Severity: 86%
Audit Metadata
Analyzed At
Sep 21, 2026, 08:18 AM
Package URL
pkg:socket/skills-sh/iuliandita%2Fskills%2Flockpick%2F@38113fadb50d8c3411941693219ce4a2fabc9d4c62a0521c3a7d1fefe9e0bcc4
Security Audit — socket — lockpick