servicemesh-tactics
Audited by Socket on Aug 12, 2026
2 alerts found:
MalwareSecurityHigh-risk malicious content: this fragment is an offensive operational playbook for Kubernetes service-mesh (Linkerd/Istio) abuse. It includes explicit disruption (Linkerd proxy /shutdown), security-control tampering (AuthorizationPolicy deletion), sensitive control-plane/debug probing (Istiod debug/*), and credential/session-oriented log scraping plus proxy secret/config retrieval. This is consistent with malicious recon, disruption, and potential information theft. Treat as unsafe and not suitable for inclusion in any production or dependency context.
High-risk offensive security skill. Its stated purpose is to attack service meshes, and its capabilities are fully aligned with exploitation: secret extraction, internal recon, lateral movement, traffic interception, and security-control bypass. No strong malware proof or suspicious installer is present, but as an AI agent skill it materially enables unauthorized intrusion and high-impact real-world actions.