offensive-osint
Audited by Socket on Aug 27, 2026
4 alerts found:
Securityx4SUSPICIOUS/HIGH-RISK skill. Its stated purpose and capabilities align, but that purpose is to equip an AI agent for offensive security reconnaissance and chained follow-on attack workflows against real targets. There is no clear malware or credential theft in the supplied file, yet the offensive scope, transitive skill loading, and unresolved install module make it unsafe to grant to a general-purpose agent.
No embedded malicious code is evidenced in this fragment (it is instructional documentation rather than a functioning dependency module with runtime compromise behavior). However, it directly enables offensive reconnaissance and targeted email list creation by combining breach/infostealer corpus queries, DNS posture inference for SSO exposure escalation, and email harvesting/pattern inference from multiple public sources and scraped content. If distributed as part of a package, treat it as high dual-use/misuse risk rather than supply-chain malware, and review intended use controls and scope.
This fragment is a credential-driven, multi-platform reconnaissance and token-triage playbook. It uses embedded/authenticated tokens to enumerate AWS IAM capabilities and logging/MFA posture, discover secret-relevant identifiers (AWS Secrets Manager/SSM, GitHub secrets metadata, Postman environment values), enumerate Slack private channels/users, and inventory accessible GitHub org/repo scope. It additionally includes explicit JWT attack testing steps (alg=none, RS→HS algorithm confusion, and HS256 brute-force guidance). No on-host malware/persistence is visible, but the operational intent and methods indicate malicious credential abuse and compromise preparation, resulting in an extremely high security risk if found in a dependency or distributed script.
The provided content is not a software dependency module; it is an attacker-style reconnaissance and identifier-extraction workflow. It enables collection of sensitive security-relevant identifiers (AWS account IDs, OAuth client IDs/scopes), Microsoft 365 tenant/provisioning and potential exposure indicators, and GraphQL schema/field discovery via error/suggestion probing. While it contains no evidence of executable supply-chain malware itself, the operational guidance is strongly malicious in intent and materially increases the capability for targeted intrusion and data exposure.