redis-attack

Fail

Audited by Socket on Aug 12, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

This skill is a high-risk offensive exploitation playbook. Its stated purpose is to attack Redis services through unauthorized access, brute force, data theft, persistence, and remote code execution, which is incompatible with a benign helper skill for general AI-agent use.

Confidence: 97%Severity: 97%
MalwareHIGH
references/attack-techniques.md

The provided fragment is unequivocally malicious operational exploitation guidance for Redis, detailing multiple high-impact compromise chains: arbitrary command execution via MODULE LOAD and Lua EVAL escape, persistence via webshell deployment and SSH authorized_keys injection, active control via reverse shells, and data exposure via Pub/Sub interception and RDB/AOF extraction. If this appears in a software repository/package distribution, it represents an extreme supply-chain risk rather than legitimate dependency code.

Confidence: 98%Severity: 100%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fredis-attack%2F@6a85b63c22139cd3f185e867ae0b9db1334e018ab9dec6b6ab3a6fe0b1e88c2e
Security Audit — socket — redis-attack