unauthorized-access-common-services
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityMalwareThis skill is a high-risk offensive exploitation playbook for AI agents. The documentation-context findings are mostly true-to-purpose rather than hidden exfiltration, and the hardcoded secret is only a placeholder, but the overall capability set is fundamentally designed for unauthorized access, persistence, data theft, and RCE across common services; that makes it unsuitable as a normal benign workflow skill even without confirmed malware behavior.
This fragment is an explicit offensive exploitation playbook that instructs unauthorized access, remote code execution, webshell/payload deployment, and credential theft/session takeover across multiple services. It is highly likely to be malicious or intended for wrongdoing if distributed within any software supply chain. While auto-execution behavior cannot be confirmed from the snippet alone, the provided content itself is dangerous and incompatible with legitimate dependency functionality.