penetration-tester
Audited by Socket on Sep 23, 2026
3 alerts found:
SecurityAnomalyx2SUSPICIOUS: the skill is internally consistent and not deceptive, with no clear malware or exfiltration behavior, but it equips an AI agent with offensive security and exploitation workflows against real targets. The main risk is high-capability abuse, not hidden data theft or supply-chain behavior.
The fragment is a penetration-testing setup and operations guide containing dual-use scanning, password-guessing, exploitation, post-exploitation, proxying, and privileged system-management commands. It presents meaningful misuse and operational supply-chain risks if run against unauthorized targets or with untrusted repositories and archives, but it contains no evident covert malicious payload, credential harvesting, exfiltration, persistence, or obfuscation. The content should be restricted to authorized testing environments and the update/restore procedures should be hardened.
The code is a transparent dual-use authentication testing script. Its main security concern is the explicit ability to launch Hydra brute-force attacks against a minimally validated URL when enabled, which can be harmful without authorization. It contains no clear supply-chain backdoor, data exfiltration, obfuscated payload, or hidden malicious behavior. The unrestricted config and output paths are operator-controlled filesystem operations, and the default-credential function only generates findings rather than authenticating.