k8s-sidecar-attack
Fail
Audited by Socket on Apr 22, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS. The skill's stated purpose is credential and secret theft via Kubernetes sidecar/shared-network packet capture. Its capabilities are fundamentally offensive, disproportionate to any benign admin task, and include explicit secret harvesting plus transitive chaining into other attack skills. Install trust is not the main issue; the core behavior itself is hostile.
Confidence: 97%Severity: 98%
Audit Metadata