privilege-escalation

Warn

Audited by Socket on Sep 24, 2026

6 alerts found:

Securityx5Anomaly
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities are broadly aligned with the stated purpose, so it is not deceptive malware, but it materially enables an AI agent to perform privilege escalation, credential harvesting, container/Kubernetes abuse, and lateral movement. No installer or hidden exfiltration path was shown, yet the operational footprint is inherently dangerous and unsuitable outside tightly authorized assessments.

Confidence: 92%Severity: 90%
SecurityMEDIUM
references/container-breakout.md

This fragment is operational container-escape and privilege-escalation guidance. It contains no evidence of automatically running malware, but following the commands in an inadequately isolated or unauthorized environment can expose credentials, modify host accounts, or grant host-level access. Treat as high-risk instructional content and verify remote tools before execution.

Confidence: 98%Severity: 86%
AnomalyLOW
references/kubernetes-privesc.md

The fragment is an attack-oriented Kubernetes security-testing guide with actionable credential-access, enumeration, and escalation instructions. It is not executable code and provides no evidence that a package automatically performs these actions; malware intent in the package cannot be established from this fragment alone. Use only in authorized environments.

Confidence: 96%Severity: 67%
SecurityMEDIUM
references/vpn-iac-secrets.md

The fragment is an offensive security and post-compromise credential-harvesting playbook. It contains highly dangerous instructions for discovering secrets, hijacking SSH agents, accessing cloud metadata, cracking Ansible Vaults, accessing Kubernetes credentials, and pivoting through networks. It does not itself demonstrate executable malware or automatic exfiltration, but use in an unauthorized context could directly enable credential theft and lateral movement. The broader file should be reviewed for execution wrappers, package scripts, or code that invokes these commands.

Confidence: 98%Severity: 90%
SecurityMEDIUM
references/linux-privesc.md

The fragment is an explicit Linux privilege-escalation and post-exploitation guide. It contains commands that can obtain root privileges, read protected files, capture network traffic, modify privileged scheduled tasks, and exploit vulnerable systems. It does not by itself demonstrate autonomous malware or package-runtime behavior because the visible content is documentation and command examples, but its intended use is clearly offensive and the operational security risk of following it is high.

Confidence: 98%Severity: 93%
SecurityMEDIUM
references/shells-and-pivoting.md

This is an offensive security and post-compromise operations cheat sheet. It contains numerous commands capable of creating reverse shells, enabling tunneling and pivoting, scanning internal networks, and transferring sensitive files. It is not executable code and shows no automatic malware behavior, persistence, credential harvesting implementation, or hidden payload. Use is restricted to authorized security testing; unauthorized execution would create a severe security risk.

Confidence: 99%Severity: 88%
Audit Metadata
Analyzed At
Sep 24, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/iuliandita%2Fskills%2Fprivilege-escalation%2F@021e9f5c1337295ddd4297ed0ba879a47af3a672de12d5452de5e9124291a6d8
Security Audit — socket — privilege-escalation