Ethical Hacking Methodology

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected The document is an accurate, thorough ethical-hacking methodology and includes many legitimate commands and tool workflows appropriate for sanctioned penetration testing. However, it also contains explicit, runnable exploitation, persistence, and anti-forensics instructions (reverse shells, Meterpreter persistence, SSH key and cron backdoors, raw dd operations) that are dual-use and materially increase the risk of misuse if executed without strict authorization and control. There is no obfuscation or covert exfiltration in the file itself, but the operational instructions warrant restricting distribution, adding stronger safety gating (lab-only examples, non-actionable pseudocode for persistence/anti-forensics, and explicit checklists for authorization), and removing or heavily qualifying procedures that create persistent access or alter production systems. LLM verification: The file is an actionable ethical-hacking/penetration-testing guide: not itself malicious code but a high-risk instructional artifact. It includes precise exploitation and reverse-shell examples, references to sensitive local files, and an insecure plaintext credential example. No obfuscated code or hidden exfiltration/C2 endpoints were found. Recommended mitigations: restrict distribution to authorized personnel, sanitize examples (replace real/cleartext credentials with placeholders), remove o

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:02 PM
Package URL
pkg:socket/skills-sh/hainamchung%2Fagent-assistant%2Fethical-hacking-methodology%2F@aafdd72dbbac639a5f60e2beb81a2b1721728313