linux-privilege-escalation
Audited by Socket on Sep 22, 2026
2 alerts found:
Securityx2SUSPICIOUS. The skill’s capabilities are internally consistent with its stated purpose, but that purpose is inherently offensive: it equips an AI agent to enumerate, exploit, escalate privileges, modify target files, and open reverse shells. The remote-tooling flow is risky but partially verifiable for PEASS-ng; the bigger concern is disproportionate autonomy for an agent skill focused on exploitation. This is not confirmed malware, but it is a high-risk offensive security skill.
This fragment is an offensive Linux privilege-escalation and post-exploitation guide containing credential-access, persistence, privileged-shell, and reverse-shell instructions. It does not itself demonstrate automatic npm package malware because it is presented as documentation and command examples, but execution of the commands could compromise a system. The fragment has high security risk as operational attack guidance, low evidence of embedded package malware, and no meaningful obfuscation.