middleware-tactics
Fail
Audited by Socket on Aug 12, 2026
2 alerts found:
MalwareSecurityMalwareevals/evals.json
HIGHMalwareHIGH
evals/evals.json
This fragment is a maliciously oriented instruction specification rather than executable library code. It explicitly guides exploitation of Tomcat and IIS (including webshell/RCE deployment and sensitive config extraction). If distributed as part of a supply-chain artifact or consumed by an automated agent, it presents very high misuse risk despite having no intrinsic runtime behavior in the snippet.
Confidence: 90%Severity: 95%
SecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
该技能与其声明目的基本一致,但其目的本身就是为 AI 代理提供中间件攻击与 getshell 方法,包含弱口令测试、WAR/JSP webshell 部署、AJP/反序列化/PUT/解析漏洞利用等高危进攻步骤。未见可疑安装源或凭据外传,但作为 AI 代理技能,它显著提升未经充分约束的真实攻击能力,应判为高风险、非恶意软件但高度危险。
Confidence: 94%Severity: 95%
Audit Metadata