attack-chain

Fail

Audited by Socket on Sep 4, 2026

4 alerts found:

SecurityMalwarex3
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities are internally consistent with its stated purpose, but that purpose is to equip an AI agent for end-to-end offensive operations, including credential theft, persistence, stealth, and evidence removal. There is no confirmed malware payload or hidden exfiltration endpoint in the text, but the real-world abuse potential and transitive trust footprint make this a high-risk offensive security skill.

Confidence: 93%Severity: 94%
MalwareHIGH
references/phases.md

This fragment is not analyzable as a software dependency/module; it is an offensive intrusion/cheat-sheet that provides actionable reconnaissance, exploitation, credential-seeking, persistence, evasion, and anti-forensics instructions. If such content exists in a repository or is packaged/distributed, it materially increases misuse risk and should be treated as malicious operational guidance rather than legitimate code.

Confidence: 78%Severity: 92%
MalwareHIGH
references/evasion-cheatsheet.md

This artifact is an adversarial malware/stealth tradecraft guide. It provides actionable instructions to bypass EDR/AV and AMSI, evade ETW/telemetry, conceal payloads in memory (injection/module stomping/memory encryption), and execute/download attacker payloads via LOLBins, followed by covert C2 transport techniques. It should be treated as high-risk malicious operational content and not as a legitimate dependency or reference material for production systems.

Confidence: 90%Severity: 100%
MalwareHIGH
references/attack-playbooks.md

The provided artifact is not a software dependency implementation; it is an explicitly adversary-oriented intrusion playbook covering end-to-end exploitation, credential theft, lateral movement, AD/AD CS abuse, phishing, and cloud metadata/token exploitation. No executable code is present in the snippet, but its content is directly reusable for wrongdoing and represents an extreme security risk if included in or distributed with a software package.

Confidence: 88%Severity: 100%
Audit Metadata
Analyzed At
Sep 4, 2026, 12:46 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fattack-chain%2F@f48bf21a474e1f643196997ff14d176f3c349e2b959a460e0c42e272e5677014
Security Audit — socket — attack-chain