k8s-storage-exploit

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s footprint is fundamentally offensive and extraction-focused. It is internally consistent with storage exploitation, but that purpose itself gives an AI agent high-risk capabilities: secret discovery, host/PV data extraction, uid/gid spoofing, and tunneling storage access through an external machine with weakened SSH verification. No strong evidence of disguised malware, but the operational risk is high.

Confidence: 96%Severity: 92%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fk8s-storage-exploit%2F@d17fc43846eea2c7eb9ebdd20c5f6fac57f3b8c0