pt-post-exploitation

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive post-exploitation capability, including credential access and lateral movement. There is no sign of malware, exfiltration endpoint, or deceptive installer, yet the operational risk is high because the skill enables impactful security actions with limited technical guardrails.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
Apr 3, 2026, 05:17 PM
Package URL
pkg:socket/skills-sh/santosomar%2Fethical-hacking-agent-skills%2Fpt-post-exploitation%2F@437f9f0d71feea225cde251c8555c5252932b7f0