escaping-containers-to-host

Fail

Audited by Socket on Aug 23, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities are consistent with its stated penetration-testing purpose, but that purpose is an offensive host-compromise playbook for AI agents. It enables container breakout, persistence, host file access, and destructive procfs actions, and it relies on third-party GitHub tooling. Not confirmed malware, but it is a high-risk exploit skill that should be tightly restricted or disallowed.

Confidence: 94%Severity: 93%
MalwareHIGH
references/api-reference.md

This fragment is an attacker-oriented container escape and host-compromise playbook. It provides actionable instructions and exact Docker Engine API abuse parameters (via /var/run/docker.sock) to create/start privileged host-integrated containers (including host filesystem binds and host PID/network modes), plus references to kernel and Kubernetes execution/persistence primitives (core_pattern, sysrq-trigger, cgroup release_agent, and static pod manifest auto-run). Even though it is not executable code in this excerpt, it is highly supply-chain relevant: distributing such material with a package materially increases the risk of misuse and indicates malicious or at minimum high-risk intent.

Confidence: 74%Severity: 95%
Audit Metadata
Analyzed At
Aug 23, 2026, 05:57 PM
Package URL
pkg:socket/skills-sh/mukul975%2Fanthropic-cybersecurity-skills%2Fescaping-containers-to-host%2F@265181fa8e2c8eb8774090c62449336d17c59a040e0311a2c6c8906c60534442
Security Audit — socket — escaping-containers-to-host