postgresql-pentesting
Audited by Socket on Aug 12, 2026
2 alerts found:
SecurityMalware该技能与其宣称的 PostgreSQL 渗透测试目的基本一致,但它向 AI Agent 提供了完整的进攻性数据库利用能力:爆破、敏感数据读取、文件读写、RCE、提权与外带。不存在明显伪装成其他用途的迹象,因此不像凭据窃取型恶意技能;但作为 AI Agent Skill,它属于高风险 offensive security 能力,应归类为高风险而非良性。
This fragment is a comprehensive PostgreSQL exploitation guide containing explicit instructions and payloads for RCE (COPY FROM PROGRAM, untrusted PL languages, LOAD of a malicious .so), persistent backdoors (config directives and session preload), privilege escalation (filenode editing of pg_authid, event triggers), file read/write, and credential extraction/exfiltration. While it is not software supply-chain code, it is highly actionable malicious guidance; if packaged into an OSS project, it constitutes severe security governance risk. No typical dependency supply-chain indicators are analyzable because there is no actual library/module code here.