exploiting-containers

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with an offensive container exploitation purpose, but that purpose gives an AI agent high-risk capabilities: container escape, Kubernetes privilege escalation, secret extraction, defense-evasion checks, and insecure API access. Third-party tool execution from raw GitHub/release binaries further raises supply-chain risk. This is not covert credential harvesting disguised as something else, but it is a dangerous offensive security skill and should be treated as high risk.

Confidence: 95%Severity: 93%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:20 AM
Package URL
pkg:socket/skills-sh/trilwu%2Fsecskills%2Fexploiting-containers%2F@e10a115d11d346cf00a46d61addb867e4d8e5ddb
Security Audit — socket — exploiting-containers