dns-pentesting
Warn
Audited by Socket on Aug 12, 2026
2 alerts found:
Securityx2SecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
该 skill 与其声明用途基本一致,但用途本身是进攻性 DNS 渗透与数据外传方法论。未见明显恶意伪装、凭据窃取或可疑安装链,但它为 AI Agent 提供了高风险的攻击、侦察、漏洞利用和 DNS 隧道/渗出能力,应归类为高风险安全/利用型 skill,而非恶意软件。
Confidence: 92%Severity: 86%
Securityreferences/dns-techniques.md
MEDIUMSecurityMEDIUM
references/dns-techniques.md
The provided content is an offensive DNS attack/recon playbook (DNS tunneling via iodine/dnscat2/dns2tcp, potential DNS amplification scanning, and guidance for extracting risky BIND configuration/TSIG secrets). It is strongly aligned with malicious or intrusion-enabling behavior rather than defensive library functionality. No legitimate software-supply-chain library code is present in the snippet.
Confidence: 85%Severity: 90%
Audit Metadata