concourse-tactics

Fail

Audited by Socket on May 9, 2026

2 alerts found:

Malwarex2
MalwareHIGH
references/attack-techniques.md

This fragment is overtly malicious Concourse CI exploitation and persistence guidance: it demonstrates credential/secret harvesting, authenticated pipeline/job manipulation, injected task execution to collect env/process/file data, exfiltration to attacker infrastructure (HTTP/DNS), and persistent backdoor behavior (periodic and webhook-triggered). Treat as hostile content; do not include or distribute it in any software supply chain. Investigate any provenance/path it may have been ingested from and remove/quarantine it.

Confidence: 90%Severity: 100%
MalwareHIGH
SKILL.md

MALICIOUS。该技能不是正常的 Concourse 运维或审计指南,而是系统化的 Concourse CI 攻击手册,直接教 AI 代理实施凭据窃取、恶意任务注入、容器利用和持久化。安装来源基本官方,但这不降低其进攻性与高危现实影响。

Confidence: 98%Severity: 98%
Audit Metadata
Analyzed At
May 9, 2026, 08:30 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fconcourse-tactics%2F@d97a61003cd30597ab49a2d6b0aa6c661fe1088a