k8s-sidecar-attack

Fail

Audited by Socket on Apr 22, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS. The skill's stated purpose is credential and secret theft via Kubernetes sidecar/shared-network packet capture. Its capabilities are fundamentally offensive, disproportionate to any benign admin task, and include explicit secret harvesting plus transitive chaining into other attack skills. Install trust is not the main issue; the core behavior itself is hostile.

Confidence: 97%Severity: 98%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fk8s-sidecar-attack%2F@c013ee40ad2c251bbaf04fafbaa098058e27477a
Security Audit — socket — k8s-sidecar-attack