bash-automation

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The document contains explicit offensive/post‑exploitation guidance (multiple reverse shell variants, system‑wide enumeration for SUID/writable files, port and host scanning, and web/subdomain enumeration). The file itself does not automatically execute or contact external infrastructure, nor does it contain obfuscated payloads or hardcoded credentials, but it provides direct, actionable techniques to achieve remote shells and local information discovery. Treat this content as high‑risk when included in a general library or unexpected package: acceptable only in controlled, authorized offensive security contexts with clear labeling and safeguards.

Confidence: 75%Severity: 70%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/duck4nh%2Fantigravity-kit%2Fbash-automation%2F@5cef397b54f0f1652b45cd5d896a9d19e98a47f1