tunneling-and-pivoting

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. The documented SSH config access is not itself malicious, but the overall skill is purpose-built to tunnel through compromised hosts, bypass segmentation, and enable lateral movement and exfiltration paths. No clear hidden behavior or installer abuse is present, but the capability set is inappropriate for a normal developer-assistance skill and should be treated as suspicious/high risk rather than confirmed malware.

Confidence: 93%Severity: 87%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:53 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Ftunneling-and-pivoting%2F@bee98061cbda739c1990751bd3d3f495110c39f0581cafcdd9e726ffc42f53ec
Security Audit — socket — tunneling-and-pivoting