tunneling-and-pivoting
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
High-risk offensive security skill. The documented SSH config access is not itself malicious, but the overall skill is purpose-built to tunnel through compromised hosts, bypass segmentation, and enable lateral movement and exfiltration paths. No clear hidden behavior or installer abuse is present, but the capability set is inappropriate for a normal developer-assistance skill and should be treated as suspicious/high risk rather than confirmed malware.
Confidence: 93%Severity: 87%
Audit Metadata