Red Team Tools and Methodology

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected This skill is a dual-use red-team / bug-bounty methodology guide and automation script. It provides powerful reconnaissance and vulnerability discovery workflows consistent with its stated purpose. I found no signs of embedded malware, obfuscation, or secret exfiltration. However, the capability set is high-risk: the automated commands and tooling can be used to perform unauthorized scanning or exploitation if operated without legal authorization. Treat this as a legitimate but potentially dangerous toolset — enforce operational scope and obtain permission before use. LLM verification: This file is a legitimate (but offensive) red-team / bug-bounty reconnaissance playbook and automation script. It contains explicit instructions for active scanning, payload injection, and fuzzing which are high-risk if used without authorization, but there is no evidence in the provided fragment of concealed malicious functionality (no hardcoded credentials, backdoors, or obfuscated payloads). Primary recommendations: (1) Verify/install third-party tools from trusted official sources and pin ve

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 17, 2026, 12:04 AM
Package URL
pkg:socket/skills-sh/automindtechnologie-jpg%2Fultimate-skill.md%2Fred-team-tools-and-methodology%2F@ffca98af1be0fa0e8755bef1e0f61c94b9face3a