privesc-windows-tokens

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its stated purpose is offensive privilege escalation and it enables an AI agent to obtain SYSTEM on Windows. There is no clear credential theft or hidden exfiltration, but the exploit-focused capability and unpinned external binaries make it high risk.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fprivesc-windows-tokens%2F@4cb0e26950b1df9c00356be4bc34c26741056eba02d24e19e258eb9f6b77bb36
Security Audit — socket — privesc-windows-tokens