pentest-tools

Fail

Audited by Socket on Sep 4, 2026

37 alerts found:

Malwarex20Securityx13Anomalyx4
MalwareHIGH
src-hunter/references/playbooks/intranet-postexp.md

High likelihood of malicious intent. The fragment is a comprehensive offensive security playbook with explicit commands for privilege escalation, UAC bypass, DLL hijacking, token impersonation, AD/Exchange/SharePoint exploitation, persistence (registry/WMI/tasks/services), reverse shells, and multiple EDR/AV evasion techniques (AMSI/ETW patching, unhooking, masquerading). This content is directly usable for compromise and persistence, so it should be treated as a severe security threat if present in a distributed package or repository.

Confidence: 85%Severity: 95%
SecurityMEDIUM
src-hunter/references/payloader/waf-bypass.md

The provided fragment is not typical open-source dependency code; it is an attack-playbook style document containing execution- and exfiltration-oriented patterns across many domains (WAF/bot bypass, RAG poisoning, JWT forgery, SSRF/IMDS credential theft, request smuggling, WebSocket attacks, CDN/cache poisoning, and CI/CD supply-chain abuse concepts). While it does not prove that a package embeds this logic, if this content is packaged/published as part of a dependency, it represents a very high security risk and requires full review of the actual repository source, entry points, and install/postinstall/build scripts before trust can be established.

Confidence: 72%Severity: 88%
SecurityMEDIUM
src-hunter/references/payloader/by-category/web/认证漏洞.md

The provided file content is a highly suspicious offensive authentication-bypass/exploitation playbook (OAuth/SAML/2FA/CAPTCHA/Remember-Me/JWT). However, the fragment contains no executable dependency code, so direct evidence of malware (e.g., secret stealing, network exfiltration, persistence, or runtime execution) cannot be confirmed from this snippet alone. Treat the package as suspicious and request the full repository/package contents to determine whether any actual runtime behavior exists beyond malicious documentation.

Confidence: 72%Severity: 85%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities align—it is plainly an offensive pentesting skill—but that purpose is inherently high risk for an AI agent because it enables scanning, exploitation, credential attacks, and post-exploitation workflows. The largest issues are broad offensive scope, third-party toolchain installation, and inconsistent container provenance for pentestMCP. The Reqable MCP path appears same-org and pinned, which lowers concern there, but overall this skill meaningfully increases security risk even without confirmed malware.

Confidence: 89%Severity: 86%
MalwareHIGH
src-hunter/references/playbooks/file-upload.md

This fragment is highly malicious exploitation/weaponization content for web upload/download bypasses, including explicit webshell/RCE verification, sensitive file disclosure via traversal/download, and arbitrary file write via Zip Slip and race conditions. It is not representative of a benign open-source dependency module. If present in a dependency package/repo, it would constitute an extreme supply-chain security risk due to its actionable attack guidance and payload templates.

Confidence: 90%Severity: 100%
MalwareHIGH
src-hunter/references/playbooks/llm-prompt-injection.md

This fragment contains explicit malicious behavior: it steals sensitive system and SSH private-key material from local disk, exfiltrates the data to an attacker-controlled HTTP endpoint, and downloads/executed additional attacker code via shell-based remote payload execution. Treat as malware/backdoor material and do not include it as a dependency; instead quarantine, revoke any exposed credentials, and validate against the original upstream source and integrity metadata.

Confidence: 90%Severity: 100%
MalwareHIGH
src-hunter/references/payloader/by-category/intranet/权限提升.md

This fragment is highly indicative of malicious intent: it is an offensive privilege-escalation and post-exploitation playbook (Windows token impersonation/Potato variants and Linux SUID/sudo/cron/kernel escalation) that includes reverse-shell execution, remote payload download-and-execute patterns, host authority changes (e.g., adding admins), and explicit EDR-evasion/stealth techniques. While there is insufficient evidence to determine whether a dependency auto-executes this content during installation/build, the shipped content itself would make the dependency unsafe to use in a supply-chain context, especially if any of it is executed or bundled with install-time scripts.

Confidence: 60%Severity: 80%
SecurityMEDIUM
src-hunter/SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to enable an AI agent to perform offensive security testing, including exploitation and post-exploitation techniques against real systems. There is no strong evidence of hidden malware, covert exfiltration, or deceptive installation, but the exploit-oriented scope, OOB evidence guidance, and credential/payload dictionaries make it a high-risk security skill rather than a benign general workflow aid.

Confidence: 93%Severity: 88%
MalwareHIGH
src-hunter/references/payloader/by-category/intranet/凭证窃取.md

The provided fragment is a highly malicious, offensive credential-harvesting and domain-compromise instruction set. It targets multiple Windows credential stores and sensitive deployment artifacts, includes plaintext WiFi password extraction guidance, provides Kerberos golden/silver ticket forging with in-memory injection, and contains explicit remote script download-and-execute patterns plus shadow-copy-based access bypass tactics. If this functionality appears in any distributed dependency, it would be an extreme security risk.

Confidence: 90%Severity: 100%
MalwareHIGH
src-hunter/references/payloader/by-category/web/框架漏洞.md

The provided fragment is highly suspicious and appears to be weaponized exploit/payload material (not legitimate dependency implementation). It explicitly describes RCE execution, deserialization/lookup triggers, persistence via webshell/WAR deployment, and outbound callback-based verification. If this content is included in or distributed with a dependency artifact, it constitutes a strong supply-chain security red flag. Additional inspection of the surrounding repository/package files (install scripts, postinstall steps, embedded binaries/assets, and runtime behavior) is required to confirm whether it is merely documentation or actively dropped/executed.

Confidence: 72%Severity: 90%
SecurityMEDIUM
src-hunter/references/payloader/by-category/web/rce远程代码执行.md

The provided fragment contains no executable dependency code; it is an offensive exploitation guide/weaponization document describing multiple RCE techniques (PHP/Java deserialization, webshell upload, file include/log poisoning, .htaccess abuse) with explicit command payload examples. While it does not prove in-module malware execution, the content is highly suspicious and would be dangerous if included in a distributed package; further inspection of the surrounding repository/package artifacts is warranted.

Confidence: 60%Severity: 78%
MalwareHIGH
src-hunter/references/playbooks/ssrf-cache-host.md

This fragment is overwhelmingly consistent with malicious exploitation/playbook instructions: it demonstrates Kubernetes ServiceAccount token abuse to enumerate permissions, list Secrets, and create a privileged host-mounted Pod (escape/cluster takeover). It also provides detailed offensive guidance for cache poisoning/deception, CDN/WAF bypass concepts, and SSRF bypass chains that can enable internal access and data theft. Treat as severe supply-chain compromise content if present in a dependency; remove/quarantine and perform incident response. Confidence is reduced only because the exact surrounding module/package code is not provided.

Confidence: 70%Severity: 100%
AnomalyLOW
src-hunter/references/payloader/by-category/intranet/信息收集.md

This fragment is not evidence of classic software-supply-chain malware (no code/payload is present, no obfuscation, no persistence or exfiltration routines shown). Instead, it is an attacker-style reconnaissance and Active Directory enumeration playbook containing highly actionable steps for discovering internal network details, SMB shares, domain users/groups, GPO/GPP password indicators, ACL privilege paths, trusts, and domain computers. The main security concern is misuse enablement: if included in a distributed package, it could meaningfully facilitate intrusion and privilege escalation, but the snippet alone cannot prove a malicious dependency or autonomous malicious behavior.

Confidence: 70%Severity: 60%
AnomalyLOW
src-hunter/references/playbooks/logic-flaws.md

该片段本身并非可执行的依赖代码,而是一份高度武器化的Web安全测试/攻击指南文档。就“是否包含供应链恶意代码/后门执行”而言,当前片段缺少任何可执行实现证据,因此无法判定存在投毒或恶意软件行为;但就“安全滥用风险”而言,其包含大量具体可操作的攻击与绕过步骤,显著降低实施门槛,若以依赖形式分发会带来较高的滥用与合规风险。建议:获取该依赖包的实际源码/入口文件、构建产物与发布内容清单(例如package.json、入口js/ts、安装/构建脚本、是否存在postinstall、是否有网络/文件/exec相关代码),仅凭当前片段不足以完成恶意代码确认。

Confidence: 70%Severity: 62%
MalwareHIGH
src-hunter/references/payloader/by-category/web/文件漏洞.md

The provided fragment is best characterized as an attacker exploitation guide rather than legitimate dependency source code. It contains highly actionable instructions and payload patterns for achieving webshell/RCE and sensitive-file disclosure via multiple common web attack primitives (upload bypass, arbitrary file read/traversal, Zip Slip, MIME/NULL-byte/extension tricks, and TOCTOU race exploitation). While the fragment does not itself demonstrate autonomous malware behavior (it is not executable code), its presence in a software package would be a serious supply-chain security red flag due to facilitation of real compromise. Further assessment would require examining surrounding repository context (file location, packaging/installation steps, and any executable scripts), which is not available here.

Confidence: 80%Severity: 85%
MalwareHIGH
src-hunter/references/playbooks/http-smuggling.md

This fragment is a weaponized HTTP request smuggling / HTTP desynchronization exploit methodology with multiple payload templates and socket-based PoC examples that directly send crafted raw HTTP byte streams to trigger proxy vs origin parsing discrepancies. It is not benign library code and is highly concerning for software supply-chain inclusion, as it meaningfully enables high-impact network exploitation (e.g., auth bypass and cache poisoning) rather than providing protective or standard functionality.

Confidence: 86%Severity: 98%
SecurityMEDIUM
src-hunter/references/payloader/by-category/web/ssrf服务端请求伪造.md

The provided fragment contains no executable logic; it is an offensive SSRF bypass and escalation playbook with highly actionable payloads targeting internal loopback addresses and follow-on compromise of Redis/MySQL (webshell/SSH/cron/INTO OUTFILE). While this specific content fragment does not prove runtime malware, its nature is strongly malicious/weaponized and would represent a serious security and supply-chain risk if included in a distributed software package.

Confidence: 62%Severity: 90%
SecurityMEDIUM
src-hunter/references/payloader/by-category/intranet/免杀与规避.md

This fragment does not contain runnable code, so direct execution/data-flow cannot be confirmed. However, it is highly suspicious: it is explicit, actionable Windows malware/EDR evasion tradecraft spanning multiple execution and stealth techniques (shellcode encryption + in-memory execution concepts, PPID/process masquerading, DLL side-loading/hijacking, command/PEB spoofing, signed-binary/LOLBAS abuse, and CLR injection). Treat the containing package as high-risk and investigate whether other files implement the described behavior (install hooks, binaries, scripts, or payload loaders).

Confidence: 62%Severity: 74%
MalwareHIGH
src-hunter/references/payloader/tools/红队工具.md

This artifact is actionable, offensive operational documentation for deploying and controlling C2/payloads and performing post-exploitation (credential dumping, token theft, lateral movement, and SOCKS pivoting). Even without embedded executable code, its direct guidance for credential/token compromise and intrusion activity makes it highly inappropriate and highly risky for a benign software supply chain dependency.

Confidence: 76%Severity: 92%
MalwareHIGH
src-hunter/references/playbooks/path-traversal.md

This fragment is not application/library code; it is an exploit guidance/write-up showing how to abuse PHP LFI vulnerabilities and stream wrappers (php://, data://, zip://, phar://) to read sensitive files, execute PHP, trigger phar deserialization RCE, and even obtain reverse shells. If this content exists within a published package, it indicates malicious intent or at least facilitation of attacks, creating a high security risk for anyone using the package blindly.

Confidence: 78%Severity: 66%
AnomalyLOW
src-hunter/references/payloader/by-category/web/csrf跨站请求伪造.md

This fragment is best characterized as CSRF/CORS/Origin/Referer/SameSite bypass exploitation guidance with example authenticated cross-site request code (`fetch` + `credentials: "include"`) and described exfiltration patterns. It contains strong offensive signals, but the provided content does not demonstrate executable malware within a dependency module (no obfuscation, no persistence, no runtime backdoor mechanisms shown). Treat as suspicious/high misuse risk for a supply-chain context, and verify the actual package contents for any executable behavior beyond instructional material.

Confidence: 65%Severity: 65%
MalwareHIGH
src-hunter/references/payloader/by-category/web/请求走私.md

This fragment is not benign application logic; it is weaponized, exploit-style code/instructions for HTTP request smuggling (TE-TE) using raw TCP-crafted HTTP/1.1 payloads with intentionally conflicting/ambiguous Transfer-Encoding and Content-Length semantics, including techniques intended to bypass security controls and potentially poison caches. Even though it does not show typical malware behaviors like persistence or exfiltration, the code’s purpose is directly offensive and would represent a severe security risk if present in a dependency.

Confidence: 78%Severity: 100%
MalwareHIGH
src-hunter/references/payloader/tools/内网渗透.md

该片段不是普通库代码,而是面向Windows/AD渗透与后渗透的操作指令集合,包含远程脚本拉取并执行(PowerShell IEX + DownloadString、curl|bash)、凭证/票据攻击(Rubeus kerberoast/asreproast/ptt、certipy ESC1/Shadow Credentials)、SAM/LSA/NTDS提取(NetExec参数)、SMB上传下载C$、以及Ligolo-ng内网隧道回连与路由等能力。若被打包/发布在软件供应链中,具有显著恶意或至少可直接用于恶意入侵的高安全风险。由于代码实现缺失且片段被截断,仍需更多上下文确认其触发方式与实际执行,但就内容性质而言高度可疑。

Confidence: 78%Severity: 92%
MalwareHIGH
src-hunter/references/payloader/tools/windows渗透.md

This PowerShell fragment is highly consistent with malicious intrusion tooling. It includes multiple direct arbitrary execution mechanisms (remote download executed via IEX, encoded command execution, execution-policy bypass), explicit AMSI defense evasion, and attacker-style reconnaissance/scanning plus recursive sensitive document discovery. While exfiltration/persistence are not demonstrated in this snippet, the execution and evasion primitives make it capable of loading subsequent malicious payloads.

Confidence: 86%Severity: 95%
SecurityMEDIUM
src-hunter/references/payloader/tools/系统命令.md

This artifact is an offensive-oriented Active Directory reconnaissance and attack-planning playbook (LDAP/DsQuery/ADExplorer + BloodHound Cypher) that identifies privileged users and privilege escalation paths (shortest paths to Domain Admins, Kerberoasting/AS-REP roasting candidates, unconstrained delegation, and ACL abuse edges). While it does not show malware execution or obfuscation in this snippet, its clear alignment with unauthorized intrusion workflows makes it high-risk from a software-supply-chain perspective if distributed as part of a dependency or automation. No direct confirmation of embedded malicious code is possible from the provided text alone.

Confidence: 62%Severity: 82%
MalwareHIGH
src-hunter/references/payloader/by-category/web/websocket安全.md

This fragment is highly suspicious and security-relevant: it provides an exploitation/PoC-oriented workflow for WebSocket/H2C request smuggling and reverse-proxy differential exploitation, plus tests for WebSocket auth/session weaknesses and unauthorized channel subscription (IDOR/vertical bypass). While it does not clearly show classic backdoor or data-stealing malware logic, it is designed for scanning internal ports via tunneling and bypassing access controls, making it inappropriate for inclusion in a benign dependency. Treat as malicious or at minimum as an exploit-testing artifact requiring removal and provenance verification.

Confidence: 68%Severity: 90%
MalwareHIGH
src-hunter/references/payloader/by-category/web/供应链攻击.md

This fragment is highly likely malicious. It combines (1) untrusted execution by running attacker-controlled input in a `run:` step, (2) supply-chain execution by running an unpinned external GitHub Action, and (3) direct exfiltration of the CI runner’s environment variables to an external domain (`https://evil.com`). Taken together, it aligns with real-world CI/CD secret-stealing and pipeline compromise patterns.

Confidence: 94%Severity: 100%
MalwareHIGH
src-hunter/references/methodology/02-bypass-toolkit.md

The provided fragment is an attacker-focused exploitation/exfiltration cheat sheet (path traversal, SSRF, WAF bypass, upload bypass) including explicit DNS/HTTP exfiltration and cloud instance metadata harvesting instructions. No legitimate library code or defensive logic is present in the shown content. While runtime malware behavior cannot be confirmed from a non-executable snippet, its inclusion would represent a high supply-chain security concern due to clear malicious intent and operational tradecraft.

Confidence: 80%Severity: 90%
SecurityMEDIUM
src-hunter/references/payloader/by-category/web/缓存与cdn安全.md

This fragment is an offensive web-attack playbook (cache poisoning, cache deception for sensitive content caching, and CDN/origin bypass) with explicit step-by-step request crafting and injection payload examples. No executable dependency code is present in the excerpt, so classical malware/persistence cannot be confirmed. Nevertheless, the content is strongly aligned with facilitating real-world compromise via caching/CDN misconfiguration and security boundary bypass, making it a high security-risk artifact if included in a software supply chain.

Confidence: 74%Severity: 88%
MalwareHIGH
src-hunter/references/playbooks/info-disclosure.md

High malicious-use risk content rather than a legitimate dependency: it provides actionable reconnaissance and exploitation instructions to extract source code/configuration/secrets from exposed endpoints (e.g., .git/.env/debug/Swagger) and then pivot to DB/API/cloud and account takeover. No obfuscation is observed. Because this is not actual package code, code-supply-chain malware cannot be confirmed, but the fragment is clearly designed to facilitate unauthorized access and credential theft.

Confidence: 86%Severity: 88%
SecurityMEDIUM
src-hunter/references/dictionaries/chinese-srcfingerprints.md

No evidence of embedded malware/backdoor behavior is present in the snippet itself (it contains no obfuscated payloads, no persistence, and no credential theft/exfiltration code). However, the fragment is highly actionable offensive reconnaissance and fuzzing guidance: it includes product fingerprinting indicators, large lists of high-risk endpoint paths (upload/RCE-adjacent/admin/info-disclosure), SQLi/business-logic parameter wordlists, spoofable header/cookie examples, and curl-based probing loops. This substantially increases an attacker’s capability to identify and target vulnerable enterprise systems if used without explicit authorization.

Confidence: 86%Severity: 83%
AnomalyLOW
src-hunter/references/industry/banking-finance.md

The provided fragment is not dependency code and therefore cannot be reviewed for classic supply-chain malware behaviors at the function/module level. However, the content is a highly actionable offensive security playbook targeting banking/payment/APP authentication and exploitation workflows. If this text appears inside a published package intended for general use, it is a significant supply-chain trust and misuse red flag. Based solely on this snippet, there is no evidence of embedded executable malware (no runtime sinks, secrets, or obfuscated payloads), but the document’s intent and operational nature warrant rejection/containment and investigation of the surrounding repository/package contents.

Confidence: 74%Severity: 62%
MalwareHIGH
src-hunter/references/playbooks/unauth-access.md

The provided fragment is not legitimate dependency source code; it is an offensive exploitation/persistence playbook with highly actionable steps for unauthorized access, credential harvesting (e.g., heapdump/env), and persistence (webshell/cron/authorized_keys). While execution by a dependency cannot be proven from this fragment alone, the content is strongly malicious in intent and would represent a serious supply-chain risk if packaged or invoked by install/build scripts. Required next step to confirm: inspect the actual dependency files/scripts for any code that executes, downloads, or applies these instructions.

Confidence: 60%Severity: 75%
SecurityMEDIUM
src-hunter/references/dictionaries/default-credentials-cn.md

This snippet is a weaponized intrusion aid (credential dictionary + scanning/fingerprinting + brute-force workflow templates + references to escalation topics). It contains no executable supply-chain malware logic, but it is directly usable to facilitate unauthorized access attempts and subsequent exploitation. Treat as high-risk malicious material; do not include in any software supply chain distribution or repository without strict authorization and controls.

Confidence: 86%Severity: 93%
SecurityMEDIUM
references/automation-loop-pattern.md

This fragment is high-risk offensive automation guidance: it specifies a loop that performs recon and vulnerability detection, then proceeds to exploit/PoC verification and evidence capture, with Burp MCP replay integration and proxy-pool-based evasion to sustain scanning. While it does not itself show embedded malicious code, distributing or embedding this workflow in a software dependency/agent framework materially increases capability for unauthorized exploitation unless strict authorization and safety guardrails are enforced externally.

Confidence: 72%Severity: 86%
MalwareHIGH
src-hunter/references/payloader/tools/密码攻击.md

该片段不是可审计的 npm/依赖库代码,而是对多种网络认证暴力破解工具与字典的直接操作说明(medusa/ncrack/crowbar/patator、以及 CrackStation 在线查询与 hashcat/john/hydra 配合)。其输入(目标/用户名/密码字典/私钥/哈希)会流向远程认证尝试与第三方在线查询,具有明显的进攻与凭据获取用途,因此供应链安全视角下风险很高。

Confidence: 70%Severity: 85%
SecurityMEDIUM
src-hunter/references/payloader/tools/隧道代理.md

This fragment is high-risk misuse-oriented content: it provides step-by-step instructions to establish reverse SOCKS/proxy tunnels, forward sensitive ports (including RDP/3389), and pivot into an internal subnet by adding routes, using a certificate verification bypass for the agent connection. While it is not malware code itself, it strongly enables unauthorized access and lateral movement if included in a distributable package or executed/invoked as part of an attack workflow.

Confidence: 72%Severity: 98%
Audit Metadata
Analyzed At
Sep 4, 2026, 12:51 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fpentest-tools%2F@f608cb75bc9ac5564f84407b8fc0619b34ac104998118c3c15d52b1eebd54ae5
Security Audit — socket — pentest-tools