middleware-tactics

Fail

Audited by Socket on Aug 12, 2026

2 alerts found:

MalwareSecurity
MalwareHIGH
evals/evals.json

This fragment is a maliciously oriented instruction specification rather than executable library code. It explicitly guides exploitation of Tomcat and IIS (including webshell/RCE deployment and sensitive config extraction). If distributed as part of a supply-chain artifact or consumed by an automated agent, it presents very high misuse risk despite having no intrinsic runtime behavior in the snippet.

Confidence: 90%Severity: 95%
SecurityMEDIUM
SKILL.md

该技能与其声明目的基本一致,但其目的本身就是为 AI 代理提供中间件攻击与 getshell 方法,包含弱口令测试、WAR/JSP webshell 部署、AJP/反序列化/PUT/解析漏洞利用等高危进攻步骤。未见可疑安装源或凭据外传,但作为 AI 代理技能,它显著提升未经充分约束的真实攻击能力,应判为高风险、非恶意软件但高度危险。

Confidence: 94%Severity: 95%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:51 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fmiddleware-tactics%2F@e0eef3850d19f0fd6f134cb3691e7707914afc081a1bed34799bcd133bf24531
Security Audit — socket — middleware-tactics