azure-pentesting

Fail

Audited by Socket on May 20, 2026

3 alerts found:

SecurityMalwarex2
SecurityMEDIUM
SKILL.md

该技能不是传统恶意载荷,但它向 AI 代理提供了高风险的云渗透与后渗透能力,并明确涉及凭据读取、令牌复用、提权、横向移动和持久化。其能力与宣称用途一致,因此更像高风险进攻性安全技能而非伪装窃密器;不过对代理开放此类能力本身就应视为高风险,且存在转移信任与敏感凭据处理问题。

Confidence: 93%Severity: 91%
MalwareHIGH
references/unauthenticated-enum.md

This fragment is an explicitly malicious, end-to-end offensive guide for Azure/Entra ID reconnaissance and compromise, including user enumeration, storage exposure probing, SAS/token misuse, password spraying, and phishing/consent flows to obtain OAuth tokens. It is not appropriate as a software dependency artifact and presents a very high security risk if distributed or used.

Confidence: 88%Severity: 90%
MalwareHIGH
references/persistence-techniques.md

This fragment is not benign code; it is an attacker playbook providing actionable Azure persistence and post-exploitation techniques, including reverse shells, Managed Identity token theft, credential/SAS generation, and explicit exfiltration steps plus detection-evasion guidance. If included in a published package, it materially increases attacker capability and is indicative of malicious content. No conventional source-to-sink analysis applies because the fragment is documentation/instructions rather than executable library logic.

Confidence: 41%Severity: 85%
Audit Metadata
Analyzed At
May 20, 2026, 09:56 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fazure-pentesting%2F@1b85ac7bd0bf2ec495a2f32ec83743c9ccfe3e30
Security Audit — socket — azure-pentesting