log-evasion

Fail

Audited by Socket on Apr 22, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

该技能与其宣称目的高度一致,但其目的本身就是为AI代理提供反日志、反取证和检测规避能力,明显超出普通DFIR/防御参考的安全边界。无明显恶意投毒式供应链迹象,但属于高风险进攻性安全技能,应判定为SUSPICIOUS而非BENIGN。

Confidence: 94%Severity: 91%
MalwareHIGH
references/linux-log-evasion.md

The provided fragment is strongly sabotage-oriented: it delivers concrete, actionable methods to disable kernel auditing, tamper with authentication and audit/session logs (including binary formats), disrupt centralized log forwarding, purge evidence via rotation, forge timestamps, and hide processes/entries using LD_PRELOAD hooking. This is highly inappropriate for a legitimate software dependency and should be treated as high-risk material for misuse.

Confidence: 84%Severity: 90%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Flog-evasion%2F@e427fe77644ddcbbbaf100391eea33dc94df39e2