cloud-penetration-testing

Warn

Audited by Socket on Sep 22, 2026

3 alerts found:

Securityx3
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. The instructions are internally consistent with a cloud penetration-testing purpose, but that purpose is inherently offensive: it teaches credential access, metadata harvesting, persistence, and data extraction across cloud providers. Install sources are mostly official, which lowers malware confidence, yet the overall skill remains high security risk because it equips an AI agent to perform real exploit actions with significant potential for misuse even with an authorization gate.

Confidence: 94%Severity: 88%
SecurityMEDIUM
references/detailed-guide.md

This is a plain-text cloud penetration-testing guide with substantial dual-use content and multiple explicit offensive and persistence procedures. It is not itself executable malware, but its instructions facilitate credential harvesting, secret extraction, data access, privilege escalation, remote command execution, and durable cloud backdoors. Use should be restricted to documented, authorized assessments with strong safeguards and removal of persistence artifacts after testing.

Confidence: 99%Severity: 88%
SecurityMEDIUM
references/advanced-cloud-scripts.md

This code fragment is not benign infrastructure automation; it is an offensive cloud pentesting toolkit that includes direct credential-access (password spraying with persistence of valid credentials), token acquisition (OAuth device-code and IMDS managed-identity token retrieval), and a tenant privilege-escalation workflow (Graph role assignment). It also performs broad sensitive configuration/data harvesting into local files. Even without obfuscation, its operational capabilities present a high security risk and strong misuse potential.

Confidence: 74%Severity: 85%
Audit Metadata
Analyzed At
Sep 22, 2026, 08:48 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fcloud-penetration-testing%2F@f23b35c5a3fa77df739cb4ab761a73969651cf89d3e5a7eb4ff664f00f2dcdac
Security Audit — socket — cloud-penetration-testing