vnc-pentesting

Warn

Audited by Socket on Aug 12, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

该 Skill 的内容与其“VNC 渗透测试”声明一致,但其实际能力是为 AI Agent 提供完整攻击链:扫描、爆破、认证绕过、凭据解密、漏洞利用和后渗透搜集。未见明确恶意植入或隐蔽外传端点,因此不属确认恶意软件;但作为 AI Agent Skill,它显著提升对外攻击与凭据获取能力,整体应判定为高风险、可疑且不应默认信任。

Confidence: 91%Severity: 88%
SecurityMEDIUM
references/vnc-techniques.md

This artifact is not malicious code, but it is an attack-enablement playbook for VNC: it provides actionable reconnaissance, authentication bypass probing, brute-force credential attempts, guidance to decrypt VNC passwords using known keys, and post-compromise automation to capture screenshots and inject commands via the remote desktop. If shipped as part of a dependency unexpectedly, it represents a high security risk due to direct misuse potential (credential compromise and data theft), even though no obfuscated or self-propagating malware logic appears here.

Confidence: 78%Severity: 92%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:53 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fvnc-pentesting%2F@42003fc695a0cea9f5cb914b0add396ad00acfec7a5100fbbdeb945741db6217
Security Audit — socket — vnc-pentesting