mssql-pentesting

Fail

Audited by Socket on Aug 12, 2026

3 alerts found:

SecurityMalwarex2
SecurityMEDIUM
SKILL.md

该 Skill 与其声明用途一致,但用途本身是面向 AI agent 的 MSSQL 攻击与后渗透。其实际能力包括爆破认证、任意命令执行、凭据窃取、横向移动和票据伪造,具有显著现实攻击性;虽非伪装型恶意软件,但应归为高风险 offensive security skill。

Confidence: 95%Severity: 97%
MalwareHIGH
references/mssql-exploitation.md

This artifact is an offensive MSSQL/AD exploitation runbook. It explicitly instructs actions that enable privilege escalation, OS command execution (xp_cmdshell and SQL Agent CmdExec), lateral movement (linked-server multi-hop and RPC OUT), and credential capture/relay (NTLM relay/UNC authentication triggers). While it is presented as documentation-like content rather than runnable package code, its intent and instructions are strongly malicious and highly unsafe to include or distribute within a software supply chain without a clearly justified defensive/authorized purpose.

Confidence: 83%Severity: 95%
MalwareHIGH
references/mssql-techniques.md

This fragment is highly malicious and not representative of benign dependency/library code. It explicitly demonstrates SQL Server-to-OS command execution (via sp_execute_external_script and related mechanisms), sensitive file disclosure, outbound SMB/NTLM credential theft triggers, linked-server lateral movement, privilege escalation, and persistence/backdoor creation via startup-enabled procedures that invoke xp_cmdshell/powershell. The overall risk is extreme; treat as active intrusion guidance rather than a software component.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fmssql-pentesting%2F@b1abdc1b377cf5696fe5ec9fd3427d142ffbee4c6c04abcf1f63795da490df6d
Security Audit — socket — mssql-pentesting