self-hosted-runner-poisoning

Fail

Audited by Socket on Sep 22, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS. The skill’s purpose is offensive exploitation of CI runners and its actual footprint matches that: approval bypass, credential theft, exfiltration to attacker-controlled endpoints, persistence installation, and log deletion. It is not a benign documentation or defensive audit skill; it operationalizes compromise and cover-up. The arbitrary pipe-to-shell installer and external exfil endpoints make the risk extreme.

Confidence: 97%Severity: 99%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/securityfortech%2Fhacking-skills%2Fself-hosted-runner-poisoning%2F@6a91653d781182c70510b2fc6f86879ec3165cb6f4ff11fecbf95b44fdeb5717
Security Audit — socket — self-hosted-runner-poisoning