analyzing-cobalt-strike-malleable-profiles

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for malware/C2 investigation and does not show credential theft or exfiltration, but it equips an AI agent with active security-scanning capability against remote hosts. Supply-chain trust is moderate rather than severe because dependencies are public and source-available, yet installs are unpinned and the JARM source is implicit.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Mar 15, 2026, 12:28 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fanalyzing-cobalt-strike-malleable-profiles%2F@32a641343f5ac9b3a19b94130123a15abc6ff2e2