privesc-enumeration

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive post-compromise enumeration and credential-harvesting capability. There is no direct exfiltration endpoint in the text, and the cited external tools are mostly same-project/official-source references, but the overall scope is inherently high risk because it directs the agent to search for secrets, collect them, and route them into follow-on exploitation workflows.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fprivesc-enumeration%2F@c173ef5ac3c5cacb1a08d9d2db4fd7cd211fb2ae12e81e1f5ec561629d1ff986
Security Audit — socket — privesc-enumeration