performing-threat-emulation-with-atomic-red-team

Warn

Audited by Socket on Apr 7, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
references/api-reference.md

The code demonstrates threat-emulation tooling that can perform remote code execution and access credential-related utilities. While intended for controlled testing, these capabilities introduce significant risk if misused or exposed publicly. Strict controls, environment isolation, input whitelisting, signed atomics, and explicit user consent are essential to mitigate potential abuse and supply-chain risks.

Confidence: 65%Severity: 60%
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill: its functionality is internally coherent for purple-team threat emulation, and the install sources are broadly legitimate, but it gives an AI agent explicit offensive security execution capability on the host. This is not confirmed malware, yet it is a high-risk security skill because it can run adversary simulations with real endpoint effects and only minimal safety scoping.

Confidence: 91%Severity: 81%
Audit Metadata
Analyzed At
Apr 7, 2026, 01:02 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-threat-emulation-with-atomic-red-team%2F@41ba4084bd8f0901d029a071b075fc62efc72840
Security Audit — socket — performing-threat-emulation-with-atomic-red-team