offensive-toctou
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the content is internally aligned with its stated purpose, but that purpose is to give an AI agent offensive exploit capability. There is no clear credential harvesting, obfuscation, or hidden exfiltration, yet the skill materially increases attack capability across binaries, kernels, containers, and web systems and can drive real-world harmful actions.
Confidence: 93%Severity: 84%
Audit Metadata