escaping-containers-to-host
Audited by Socket on Aug 23, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS/HIGH-RISK skill. Its capabilities are consistent with its stated penetration-testing purpose, but that purpose is an offensive host-compromise playbook for AI agents. It enables container breakout, persistence, host file access, and destructive procfs actions, and it relies on third-party GitHub tooling. Not confirmed malware, but it is a high-risk exploit skill that should be tightly restricted or disallowed.
This fragment is an attacker-oriented container escape and host-compromise playbook. It provides actionable instructions and exact Docker Engine API abuse parameters (via /var/run/docker.sock) to create/start privileged host-integrated containers (including host filesystem binds and host PID/network modes), plus references to kernel and Kubernetes execution/persistence primitives (core_pattern, sysrq-trigger, cgroup release_agent, and static pod manifest auto-run). Even though it is not executable code in this excerpt, it is highly supply-chain relevant: distributing such material with a package materially increases the risk of misuse and indicates malicious or at minimum high-risk intent.