cve-2026-31431-copy-fail

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its behavior is internally consistent with its stated purpose, but that purpose is to arm an AI agent with local privilege-escalation capability and optional root-shell execution. There is no obvious network exfiltration or hidden credential harvesting, so this is not confirmed malware, but it is an offensive exploit skill with significant security risk.

Confidence: 94%Severity: 88%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:29 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fcve-2026-31431-copy-fail%2F@818bb555611cdd0758e4fc427fe2ae64ba7fed09