redis-attack
Audited by Socket on Aug 12, 2026
2 alerts found:
Malwarex2This skill is a high-risk offensive exploitation playbook. Its stated purpose is to attack Redis services through unauthorized access, brute force, data theft, persistence, and remote code execution, which is incompatible with a benign helper skill for general AI-agent use.
The provided fragment is unequivocally malicious operational exploitation guidance for Redis, detailing multiple high-impact compromise chains: arbitrary command execution via MODULE LOAD and Lua EVAL escape, persistence via webshell deployment and SSH authorized_keys injection, active control via reverse shells, and data exposure via Pub/Sub interception and RDB/AOF extraction. If this appears in a software repository/package distribution, it represents an extreme supply-chain risk rather than legitimate dependency code.