aws-penetration-testing
Audited by Socket on Sep 17, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS/HIGH-RISK skill. Its stated purpose is offensive AWS exploitation, and the capabilities match that purpose, but the purpose itself grants an AI agent attack-oriented actions: credential theft from metadata, privilege escalation, persistence, log evasion, and remote command execution. The install sources are mostly plausible security tools, yet unpinned third-party installs add supply-chain risk. Not confirmed malware, but it is an unsafe offensive-security skill with substantial real-world abuse potential.
This artifact is a high-misuse training/playbook that includes explicit malicious Lambda privilege-escalation code (AdministratorAccess via IAM policy attachment) and actionable backdooring/persistence instructions (Lambda code update and invocation), along with abuse-ready workflows for secrets/KMS, enumeration, and container tampering. While it is not demonstrated as executable package malware in the provided fragment, its content is strongly indicative of intentional offensive capability and should be treated as a serious security/supply-chain red flag if included in a dependency or distributed software package.