aws-penetration-testing
Audited by Socket on Aug 11, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, but that purpose is to equip an AI agent with offensive AWS tradecraft including credential theft, privilege escalation, persistence, and logging evasion. Install sources are partly legitimate but still include unpinned third-party tooling and credential forwarding to external code, so overall security risk is high even without clear evidence of hidden malware.
This artifact is a high-misuse training/playbook that includes explicit malicious Lambda privilege-escalation code (AdministratorAccess via IAM policy attachment) and actionable backdooring/persistence instructions (Lambda code update and invocation), along with abuse-ready workflows for secrets/KMS, enumeration, and container tampering. While it is not demonstrated as executable package malware in the provided fragment, its content is strongly indicative of intentional offensive capability and should be treated as a serious security/supply-chain red flag if included in a dependency or distributed software package.