snmp-pentesting
Fail
Audited by Socket on Aug 12, 2026
2 alerts found:
SecurityMalwareSecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
该技能不是普通运维或审计指南,而是专门为 AI Agent 提供 SNMP 攻击、凭据爆破、远程命令执行、配置窃取与反弹 shell 的操作手册。其能力与声明一致,但声明本身就是进攻性利用;再叠加从个人 GitHub 克隆并执行第三方工具且向其传入 RW community,整体应判为高风险、可疑且不适合默认信任的技能。
Confidence: 95%Severity: 94%
Malwarereferences/snmp-techniques.md
HIGHMalwareHIGH
references/snmp-techniques.md
This fragment is highly indicative of malicious exploitation and post-exploitation guidance. It demonstrates (1) SNMP-based configuration exfiltration (copy running-config to attacker-controlled TFTP), and (2) NET-SNMP-EXTEND-MIB command execution with an embedded reverse-shell payload triggered via SNMP read behavior. If present in any dependency or repository, it represents an extreme supply-chain security concern. No benign or defensive use case is demonstrated in the provided content.
Confidence: 82%Severity: 99%
Audit Metadata