harbor-tactics

Fail

Audited by Socket on Aug 12, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

MALICIOUS. The skill’s declared purpose is offensive Harbor compromise, and its actual footprint matches that: credential attacks, secret harvesting, exfiltration to attacker infrastructure, persistent robot accounts, and supply-chain backdooring with a reverse shell. Even without hidden code or an installer, this is a high-risk exploit skill incompatible with benign developer-assistance use.

Confidence: 99%Severity: 99%
MalwareHIGH
references/attack-techniques.md

This fragment is strongly indicative of malicious Harbor compromise tooling. While it begins with vulnerability enumeration, it also performs persistence (creates and elevates a new sysadmin account with hardcoded credentials), credential tampering (resets other users’ passwords), monitoring reconnaissance with explicit evasion guidance, governance/provenance bypass (labeling and disabling immutable tag rules), potential upstream credential exposure via proxy-cache/registry inspection, and manual GC intended to destroy prior image layers/evidence. Do not trust or reuse this logic in any environment.

Confidence: 90%Severity: 98%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fharbor-tactics%2F@816d04811f6260ae21c5e62c5dd5613fdf482750f77e1a877f895ec404dda0da
Security Audit — socket — harbor-tactics