redis-pentesting
Audited by Socket on Aug 12, 2026
2 alerts found:
Securityx2该 Skill 的行为与其“Redis 渗透测试”目的基本一致,但它本质上是面向 AI Agent 的进攻性安全/利用指南,包含爆破、数据提取、文件植入、凭据滥用、RCE 与反弹 shell。未见明显伪装或隐蔽外传,因此不属确认恶意软件;但其可操作的攻击能力、对第三方 exploit 代码的依赖以及高影响自主动作,使其整体应判为高风险、可疑的攻击型 Skill。
The provided artifact is an offensive, highly actionable Redis exploitation guide. It contains concrete instructions and payloads for RCE and persistence (webshell writing, cron persistence, SSH authorized_keys injection), plus native module loading, rogue replication workflows, and SSRF-to-Redis chaining into application execution. While it is not executable code, its distribution as part of a software package is a serious supply-chain security concern because it materially enables unauthorized compromise of Redis and related systems.