kernel-exploitation

Warn

Audited by Socket on Jul 21, 2026

3 alerts found:

Securityx3
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and uses mostly official/local tooling, so there is little evidence of malware or credential theft. However, its stated purpose is to enable kernel exploitation and privilege escalation, giving an AI agent offensive security capability with real-world attack guidance; this makes the skill high risk despite benign supply-chain characteristics.

Confidence: 92%Severity: 78%
SecurityMEDIUM
KERNEL_HEAP_TECHNIQUES.md

The provided file is an explicitly offensive, highly actionable Linux kernel heap exploitation playbook. It details how to manipulate SLUB allocator behavior and specific kernel objects (msg_msg, pipe_buffer, sk_buff) to achieve UAF/OOB-based primitives including arbitrary read/write and potential control-flow via function-pointer paths, and it includes race stabilization tactics. Even though there is no executable malware in this snippet, its presence in a software dependency is a serious supply-chain misuse/weaponization risk. Additional package-level behavior cannot be assessed from this fragment alone.

Confidence: 72%Severity: 88%
SecurityMEDIUM
KERNEL_MITIGATION_BYPASS.md

This fragment is not benign software logic; it is exploit-development/weaponization documentation aimed at bypassing major Linux kernel mitigations to achieve kernel code execution and privilege escalation. No actual runtime malicious behavior (I/O/exfiltration/command execution) is implemented in the fragment itself, but its distribution as part of a software dependency would represent a high supply-chain security concern due to the clear offensive intent and actionable bypass guidance.

Confidence: 82%Severity: 90%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fkernel-exploitation%2F@9a945b2df61efc4140e40a75f1e7b4b598397e9e96bc43bb69af77f758b619f3
Security Audit — socket — kernel-exploitation