container-security

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a legitimate container and Kubernetes security assessment guide containing step-by-step commands and checklists for vulnerability scanning, hardening, and escape testing. It does not contain embedded malicious code or obfuscated payloads, but it includes several high-risk operational patterns: download-and-execute installer scripts (curl | bash), cloning and running third-party scripts, examples that mount/chroot host filesystems, and instructions for active penetration testing. These are appropriate for offensive/defensive testing contexts but are dangerous if executed without authorization or in production environments. The primary risks are supply-chain (running remote install scripts), privilege escalation (mount/chroot, sudo), and misuse of powerful tools (kube-hunter active scans, kubectl apply remote job). Operators should treat the document as guidance only, verify and pin installer sources, run tests in isolated environments, and require explicit authorization before active testing.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:56 AM
Package URL
pkg:socket/skills-sh/hardw00t%2Fai-security-arsenal%2Fcontainer-security%2F@c58e14e25807d7d8c0a08060ac888c1a7dcf71d8