aws-penetration-testing

Fail

Audited by Socket on Sep 17, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose is offensive AWS exploitation, and the capabilities match that purpose, but the purpose itself grants an AI agent attack-oriented actions: credential theft from metadata, privilege escalation, persistence, log evasion, and remote command execution. The install sources are mostly plausible security tools, yet unpinned third-party installs add supply-chain risk. Not confirmed malware, but it is an unsafe offensive-security skill with substantial real-world abuse potential.

Confidence: 93%Severity: 90%
MalwareHIGH
references/advanced-aws-pentesting.md

This artifact is a high-misuse training/playbook that includes explicit malicious Lambda privilege-escalation code (AdministratorAccess via IAM policy attachment) and actionable backdooring/persistence instructions (Lambda code update and invocation), along with abuse-ready workflows for secrets/KMS, enumeration, and container tampering. While it is not demonstrated as executable package malware in the provided fragment, its content is strongly indicative of intentional offensive capability and should be treated as a serious security/supply-chain red flag if included in a dependency or distributed software package.

Confidence: 70%Severity: 90%
Audit Metadata
Analyzed At
Sep 17, 2026, 03:14 PM
Package URL
pkg:socket/skills-sh/zebbern%2Fclaude-code-guide%2Faws-penetration-testing%2F@7c2508c3a5f98506fedb65d472abea1b0848d4b80d6891b26416d255f9f7637e
Security Audit — socket — aws-penetration-testing