redis-pentesting

Warn

Audited by Socket on Aug 12, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

该 Skill 的行为与其“Redis 渗透测试”目的基本一致,但它本质上是面向 AI Agent 的进攻性安全/利用指南,包含爆破、数据提取、文件植入、凭据滥用、RCE 与反弹 shell。未见明显伪装或隐蔽外传,因此不属确认恶意软件;但其可操作的攻击能力、对第三方 exploit 代码的依赖以及高影响自主动作,使其整体应判为高风险、可疑的攻击型 Skill。

Confidence: 93%Severity: 94%
SecurityMEDIUM
references/redis-techniques.md

The provided artifact is an offensive, highly actionable Redis exploitation guide. It contains concrete instructions and payloads for RCE and persistence (webshell writing, cron persistence, SSH authorized_keys injection), plus native module loading, rogue replication workflows, and SSRF-to-Redis chaining into application execution. While it is not executable code, its distribution as part of a software package is a serious supply-chain security concern because it materially enables unauthorized compromise of Redis and related systems.

Confidence: 78%Severity: 88%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fredis-pentesting%2F@d271515e77f776b350ca0f993aa62abf19eecc6261d2e8b6fd87e4b44ff30db8
Security Audit — socket — redis-pentesting