penetration-testing
Audited by Socket on Aug 4, 2026
3 alerts found:
Malwarex2SecurityThis fragment is highly indicative of malicious behavior: it contains multi-phase intrusion workflow components including privilege escalation (Linux/Windows), credential/hash abuse, lateral movement (remote execution), tunneling/pivoting (SSH/chisel/FRP), and explicit data exfiltration techniques (DNS/HTTP/ICMP/encrypted socket and steganography). If found inside a dependency or supply-chain package, it should be treated as a likely compromise tool/payload rather than legitimate software.
High risk malicious/offensive content: the snippet provides concrete container/Kubernetes/cloud escape and privilege escalation steps, including credential/secret targeting (/etc/shadow) and retrieval of cloud IAM credentials from instance metadata (169.254.169.254), plus authenticated Kubernetes API calls to create privileged pods. This strongly indicates intent to compromise systems rather than legitimate functionality.
SUSPICIOUS: the skill is purpose-aligned but inherently high risk because it arms an AI agent with penetration-testing procedures and potentially state-changing security operations. There is no direct malware, installer abuse, or exfiltration in the provided text, but offensive-security enablement and broad trigger scope make it dangerous in agent environments.