attack-chain

Fail

Audited by Socket on Aug 19, 2026

3 alerts found:

Malwarex3
MalwareHIGH
SKILL.md

High-risk offensive agent skill. Its stated purpose matches its capabilities, but those capabilities are inherently dangerous for an AI agent: multi-stage attack orchestration, credential theft, persistence, evasion, anti-forensics, and delegation to more tooling/skills. Not enough evidence for confirmed malware, but it is a severe security risk and should be treated as a dangerous exploit/orchestration skill.

Confidence: 95%Severity: 97%
MalwareHIGH
references/evasion-cheatsheet.md

This artifact is an adversarial malware/stealth tradecraft guide. It provides actionable instructions to bypass EDR/AV and AMSI, evade ETW/telemetry, conceal payloads in memory (injection/module stomping/memory encryption), and execute/download attacker payloads via LOLBins, followed by covert C2 transport techniques. It should be treated as high-risk malicious operational content and not as a legitimate dependency or reference material for production systems.

Confidence: 90%Severity: 100%
MalwareHIGH
references/attack-playbooks.md

The provided artifact is not a software dependency implementation; it is an explicitly adversary-oriented intrusion playbook covering end-to-end exploitation, credential theft, lateral movement, AD/AD CS abuse, phishing, and cloud metadata/token exploitation. No executable code is present in the snippet, but its content is directly reusable for wrongdoing and represents an extreme security risk if included in or distributed with a software package.

Confidence: 88%Severity: 100%
Audit Metadata
Analyzed At
Aug 19, 2026, 09:13 AM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fattack-chain%2F@721d83ae4ca78a5dcd3f27704af44114173d43c55e8e41283ffae8c55ec2803c
Security Audit — socket — attack-chain