arbitrary-write-to-rce

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive exploit tradecraft for converting arbitrary write bugs into RCE and root compromise. There is no clear credential theft or covert exfiltration, so it is not confirmed malware, but it is a high-risk exploit-enablement skill with mutable install trust and transitive skill references.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Farbitrary-write-to-rce%2F@728c24142f937110281e315f2bcf2466d3581f70a6778c9825cb21e6d4e55ca8
Security Audit — socket — arbitrary-write-to-rce