offensive-dependency-confusion

Fail

Audited by Socket on Aug 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill is internally coherent as an offensive security methodology, but that purpose itself is dangerous for an AI agent: it teaches targeted supply-chain compromise, routes execution beacons to known exfiltration endpoints, and instructs autonomous public-registry publishing. Not confirmed malware by itself, but it materially enables real attacks and should be treated as a high-risk offensive skill.

Confidence: 97%Severity: 96%
Audit Metadata
Analyzed At
Aug 27, 2026, 02:27 PM
Package URL
pkg:socket/skills-sh/snailsploit%2Fclaude-red%2Foffensive-dependency-confusion%2F@30d759e6d9e2fe9b858779991dd378bdf580ff60677a57e6fe02a7b4b273d7d2
Security Audit — socket — offensive-dependency-confusion