database-tactics

Fail

Audited by Socket on Aug 12, 2026

5 alerts found:

Securityx4Malware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned but its purpose is offensive exploitation. It equips an AI agent to brute-force, exploit, execute commands, write files, escalate privileges, and extract data from databases and underlying hosts. No strong malware or concealment signals appear, but the operational security risk is high.

Confidence: 94%Severity: 90%
SecurityMEDIUM
references/mssql-attack.md

This artifact is not a software module; it is an attacker-focused MSSQL exploitation guide describing credential guessing, SQL-to-OS command execution (xp_cmdshell/CLR/Agent/linked servers), file read/write via SQL primitives, privilege escalation, and NTLM hash harvesting through UNC authentication to an external listener. It contains no code obfuscation, but it is highly actionable for unauthorized compromise and credential theft. In a supply-chain context, its presence in a dependency/package repository would be a major security governance red flag even though it is not itself a deployable malware payload.

Confidence: 90%Severity: 78%
MalwareHIGH
references/postgresql-attack.md

This fragment is an explicit offensive PostgreSQL compromise guide, describing credential brute force/auth bypass, potential RCE via PostgreSQL command-execution features (COPY FROM PROGRAM / procedural language/UDF paths), filesystem read/write via database primitives, sensitive data extraction (including password hash references), privilege escalation, and Windows NTLM hash capture via UNC-trigger + Responder. If this content appears in a repository or dependency, it is a strong indicator of malicious intent and should be treated as a severe supply-chain security concern.

Confidence: 76%Severity: 98%
SecurityMEDIUM
evals/evals.json

该工件不包含可执行恶意逻辑(无网络/命令/文件/执行器),因此无法直接证明运行时恶意行为;但其内容为跨 Redis/MSSQL/PostgreSQL 获取操作系统 shell/命令执行的攻击剧本级指导,属于强攻击使能与高滥用风险。建议将其视为高风险供给内容:限制分发、移除攻击性提示或替换为合规的防御/检测导向材料,并对下游使用进行治理。

Confidence: 86%Severity: 75%
SecurityMEDIUM
references/redis-attack.md

This fragment is not a software module; it is directly actionable offensive documentation for compromising Redis. It describes multiple high-impact attack paths (unauthorized access and brute forcing, replication-based module RCE, Lua sandbox escape via EVAL, and enumeration/extraction). If included in a dependency package, it is a strong malicious-content supply-chain red flag. No embedded malware behavior can be confirmed from this text alone, but the intent and operational exploit guidance are clear.

Confidence: 70%Severity: 78%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fdatabase-tactics%2F@760e26f66ba46f714e747e837d35b546d5f0d6eef82156b8a7d79fce837e1eec
Security Audit — socket — database-tactics