unauthorized-access-common-services

Fail

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

This skill is a high-risk offensive exploitation playbook for AI agents. The documentation-context findings are mostly true-to-purpose rather than hidden exfiltration, and the hardcoded secret is only a placeholder, but the overall capability set is fundamentally designed for unauthorized access, persistence, data theft, and RCE across common services; that makes it unsuitable as a normal benign workflow skill even without confirmed malware behavior.

Confidence: 97%Severity: 96%
MalwareHIGH
PORT_SERVICE_MATRIX.md

This fragment is an explicit offensive exploitation playbook that instructs unauthorized access, remote code execution, webshell/payload deployment, and credential theft/session takeover across multiple services. It is highly likely to be malicious or intended for wrongdoing if distributed within any software supply chain. While auto-execution behavior cannot be confirmed from the snippet alone, the provided content itself is dangerous and incompatible with legitimate dependency functionality.

Confidence: 85%Severity: 100%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:16 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Funauthorized-access-common-services%2F@7ab15e112bcfd618473f4ad3c4b810dcbfcac77f4b4df91de4bd157e38f64566
Security Audit — socket — unauthorized-access-common-services