privesc-enumeration
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive post-compromise enumeration and credential-harvesting capability. There is no direct exfiltration endpoint in the text, and the cited external tools are mostly same-project/official-source references, but the overall scope is inherently high risk because it directs the agent to search for secrets, collect them, and route them into follow-on exploitation workflows.
Confidence: 95%Severity: 90%
Audit Metadata