exploiting-aws-with-pacu

Warn

Audited by Socket on Aug 4, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities are internally consistent with its stated purpose, and install sources are mostly official, but it gives an AI agent instructions to ingest AWS credentials, enumerate accounts, escalate privileges, establish persistence, and extract cloud data. This is not confirmed malware, but it is a dangerous agent capability set with substantial real-world impact.

Confidence: 94%Severity: 88%
AnomalyLOW
references/api-reference.md

This snippet is documentation describing an offensive AWS exploitation framework with modules for IAM persistence/backdoors, EC2 startup-script injection, and S3/secrets data access likely suitable for exfiltration. No executable implementation is present here, so hidden malware, obfuscation, concrete network/filesystem effects, and exact source-to-sink flows cannot be verified from this fragment alone. Risk remains elevated due to the explicit hostile-capability descriptions, but malware cannot be conclusively confirmed without the actual code that implements these modules.

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
Aug 4, 2026, 02:42 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fexploiting-aws-with-pacu%2F@43dcb61e49515c97021fb8bf9f49274a518b0eb6cf25a0faaddc4b467f2afa28
Security Audit — socket — exploiting-aws-with-pacu