exploiting-cloud-platforms

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The offensive purpose aligns with the exploitation capabilities, so the issue is not hidden intent but scope and trust: the skill meaningfully enables cloud privilege escalation, secret retrieval, and metadata-token abuse, and it references several unverifiable third-party tools without provenance. No clear credential exfiltration endpoint is shown, but credential forwarding to external offensive tooling and high-impact cloud actions make this a high-risk skill.

Confidence: 91%Severity: 83%
AnomalyLOW
references/azure-command-reference.md

This is dual-use Azure security and exploitation documentation. It presents commands that can expose cloud inventory, stored data, secrets, and managed-identity tokens when executed with access, and it includes an insecure plaintext command-line credential example. The fragment contains no executable malware, persistence, covert exfiltration, or package-install behavior; risk derives from the documented capabilities and potential unauthorized use.

Confidence: 99%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 11:07 AM
Package URL
pkg:socket/skills-sh/trilwu%2Fsecskills%2Fexploiting-cloud-platforms%2F@4d7bfe062b50621564349496d8d4e028b441dec1846fb7d0117774473eba9844
Security Audit — socket — exploiting-cloud-platforms