ssh-pentesting

Warn

Audited by Socket on Aug 12, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

该 Skill 的描述与内容一致,但其一致的目的本身就是为 AI Agent 提供完整的 SSH 攻击与横向移动能力。未见明显恶意隐藏安装器或固定窃密端点,因此更适合判定为高风险攻击技能而非确认型恶意软件。

Confidence: 96%Severity: 97%
SecurityMEDIUM
references/ssh-techniques.md

This fragment is not code implementing a library; it is an offensive SSH/pentesting/compromise playbook. It provides clear operational guidance to enable tunneling-based access, SSH key/agent discovery and reuse, SFTP abuse concepts, and SSH MitM credential interception, plus references to exploitation/testing workflows. No obfuscation is present, and there is no evidence of a hidden executable payload in the provided text alone. In a supply-chain scenario, however, publishing or bundling this material is highly suspicious from a misuse standpoint and warrants deeper inspection of surrounding package behavior (e.g., install-time scripts, runtime execution, and whether any automation is triggered).

Confidence: 72%Severity: 90%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:53 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fssh-pentesting%2F@5dbfa4bcc6de597412785c646e7d927825c6b51eea948bda340cc30c2063d5e2
Security Audit — socket — ssh-pentesting