memcache-pentesting

Warn

Audited by Socket on Aug 12, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

该 Skill 与其声明目的内部一致,但目的本身是为 AI Agent 提供完整的 Memcached 攻击能力:扫描、未授权访问验证、敏感缓存提取、DDoS 放大评估、漏洞利用和缓存投毒。安装来源整体正常,未见明显供应链欺骗;主要风险来自面向真实目标的 offensive security 能力与远端敏感数据提取,因此应判为高风险而非确认恶意。

Confidence: 94%Severity: 91%
SecurityMEDIUM
references/memcache-techniques.md

The reviewed artifact is a high-risk offensive Memcached exploitation guide. While it does not constitute executable malware code within a dependency, it meaningfully enables malicious actions: (1) enumeration and extraction of cached keys/values, (2) session/cache poisoning via crafted 'set' writes, and (3) potential UDP reflection/amplification abuse. If included in a repository or software supply chain as documentation/material, it should be treated as a serious security policy and misuse risk.

Confidence: 80%Severity: 88%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fmemcache-pentesting%2F@221636db84e3d560cec3a22d432da8abf45be2a16e18d5a1a2a9f3e09775c069
Security Audit — socket — memcache-pentesting