smb-pentesting

Fail

Audited by Socket on Aug 12, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

该技能与其声明目的基本一致,但其目的本身就是为 AI Agent 提供完整的 SMB 攻击与后渗透作战手册。未见明显伪装、偷传到陌生中转站或恶意安装器,因此不像“伪装型恶意技能”;但它赋予 Agent 高危进攻能力、凭据获取与远程执行路径,应归类为高风险而非良性。

Confidence: 93%Severity: 95%
MalwareHIGH
references/smb-exploitation.md

This artifact is best characterized as an attacker-oriented SMB exploitation and credential theft/relay playbook packaged as documentation. It provides explicit, actionable steps and command examples for scanning and exploiting SMB vulnerabilities, coercing victim authentication (SMB Trap), capturing NetNTLMv2 credentials (Responder), relaying them (ntlmrelayx), cracking hashes, and using them for further remote execution. No obfuscation is present; the maliciousness signal is the operational offensive content itself. If included in a software dependency, it should be treated as a serious supply-chain compromise/misuse risk and investigated/removed.

Confidence: 82%Severity: 95%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:53 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fsmb-pentesting%2F@7c6dac0f802cf3bea78d87d127c999cd599eba578d93ef196a4f25e93d51abb6
Security Audit — socket — smb-pentesting