voip-pentesting

Warn

Audited by Socket on Aug 12, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

该 Skill 与其声明的 VoIP/SIP 渗透测试目的基本一致,但它本质上是面向 AI Agent 的进攻性安全技能,直接教授认证攻击、通话窃听/劫持、DoS、凭据提取与后渗透。未见明显伪装安装链或外部窃密端点,因此不像伪装型恶意技能;但按用途与能力范围应判定为高风险、可被滥用于未授权攻击的安全技能。

Confidence: 95%Severity: 93%
SecurityMEDIUM
references/voip-techniques.md

This provided fragment is not software implementation code; it is an attacker-oriented VoIP exploitation/abuse guide with explicit operational commands and configuration examples for causing unauthorized media interception/injection, spying/recording, and potential admin/dialplan command execution in Asterisk if misconfigured. There is no evidence of obfuscation or embedded executable payload in the fragment itself, but the inclusion of highly actionable intrusion guidance is a meaningful security-risk signal for a supply-chain package if shipped as part of a dependency. Additional context from the actual package contents is required to confirm whether it is merely documentation or part of a malicious distribution.

Confidence: 58%Severity: 72%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:53 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fvoip-pentesting%2F@63e7f8b6475b1548fd207469c000e634f8b471ba28a975dc0da67a04b3c40db3
Security Audit — socket — voip-pentesting