offensive-toctou

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the content is internally aligned with its stated purpose, but that purpose is to give an AI agent offensive exploit capability. There is no clear credential harvesting, obfuscation, or hidden exfiltration, yet the skill materially increases attack capability across binaries, kernels, containers, and web systems and can drive real-world harmful actions.

Confidence: 93%Severity: 84%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:33 PM
Package URL
pkg:socket/skills-sh/snailsploit%2Fclaude-red%2Foffensive-toctou%2F@1c962d3b101dc3a726ea62e546a66b7377357484682a639832d3c292ad7a6090
Security Audit — socket — offensive-toctou