privesc-check

Warn

Audited by Socket on Mar 30, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
evals/evals.json

No executable malware code is present in the snippet, but it is an explicitly offensive privilege-escalation instruction dataset for both Linux and Windows, including concrete command sequences and named exploitation technique families aimed at obtaining elevated privileges (SYSTEM). If this artifact is consumed by an automated agent or included in a software dependency, it materially increases misuse capability and should be treated as high security risk unless tightly scoped and authorized.

Confidence: 78%Severity: 88%
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities align with its stated purpose, but that purpose is explicit AI-assisted privilege-escalation on compromised systems, which materially increases misuse risk even without malware, exfiltration, or suspicious installers.

Confidence: 93%Severity: 84%
Audit Metadata
Analyzed At
Mar 30, 2026, 02:21 AM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fprivesc-check%2F@4833af09a96614d9c76cecd2b856caa84102b5d5