arbitrary-write-to-rce
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive exploit tradecraft for converting arbitrary write bugs into RCE and root compromise. There is no clear credential theft or covert exfiltration, so it is not confirmed malware, but it is a high-risk exploit-enablement skill with mutable install trust and transitive skill references.
Confidence: 93%Severity: 90%
Audit Metadata