Red Team Tools and Methodology

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill presents a coherent, end-to-end red-team reconnaissance workflow with explicit toolchains and deliverables. Its footprint—broad access to external services, multiple third-party tools, and extensive data aggregation—is proportionate to its stated purpose of automation for security research, but it introduces notable credential handling and data-exfiltration risks. The use of API keys and external lookups without clear secret-management or access-control prompts a suspicious-to-moderate risk posture. Overall, the footprint is plausible for a security-research oriented toolset, but requires strict credential handling, access controls, audit logging, and explicit user consent boundaries to be considered BENIGN. Given the current description, classify as SUSPICIOUS due to credential exposure potential and broad data flows, with elevated attention to supply-chain risk.

Confidence: 75%Severity: 60%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:15 AM
Package URL
pkg:socket/skills-sh/claudiodearaujo%2Fizacenter%2Fred-team-tools-and-methodology%2F@ffca98af1be0fa0e8755bef1e0f61c94b9face3a