vnc-pentesting
Audited by Socket on Aug 12, 2026
2 alerts found:
Securityx2该 Skill 的内容与其“VNC 渗透测试”声明一致,但其实际能力是为 AI Agent 提供完整攻击链:扫描、爆破、认证绕过、凭据解密、漏洞利用和后渗透搜集。未见明确恶意植入或隐蔽外传端点,因此不属确认恶意软件;但作为 AI Agent Skill,它显著提升对外攻击与凭据获取能力,整体应判定为高风险、可疑且不应默认信任。
This artifact is not malicious code, but it is an attack-enablement playbook for VNC: it provides actionable reconnaissance, authentication bypass probing, brute-force credential attempts, guidance to decrypt VNC passwords using known keys, and post-compromise automation to capture screenshots and inject commands via the remote desktop. If shipped as part of a dependency unexpectedly, it represents a high security risk due to direct misuse potential (credential compromise and data theft), even though no obfuscated or self-propagating malware logic appears here.