ssh-pentesting
Audited by Socket on Aug 12, 2026
2 alerts found:
Securityx2该 Skill 的描述与内容一致,但其一致的目的本身就是为 AI Agent 提供完整的 SSH 攻击与横向移动能力。未见明显恶意隐藏安装器或固定窃密端点,因此更适合判定为高风险攻击技能而非确认型恶意软件。
This fragment is not code implementing a library; it is an offensive SSH/pentesting/compromise playbook. It provides clear operational guidance to enable tunneling-based access, SSH key/agent discovery and reuse, SFTP abuse concepts, and SSH MitM credential interception, plus references to exploitation/testing workflows. No obfuscation is present, and there is no evidence of a hidden executable payload in the provided text alone. In a supply-chain scenario, however, publishing or bundling this material is highly suspicious from a misuse standpoint and warrants deeper inspection of surrounding package behavior (e.g., install-time scripts, runtime execution, and whether any automation is triggered).