conducting-cloud-infrastructure-penetration-test

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior matches its stated pentest purpose, but that purpose is itself high risk: it gives an AI agent offensive cloud-security capabilities, direct credential handling, metadata-token extraction, and exploit/backdoor workflows. Install provenance is mostly legitimate, yet the overall skill should be treated as high risk due to offensive use, credential forwarding, and real-world cloud actions.

Confidence: 95%Severity: 91%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:22 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fconducting-cloud-infrastructure-penetration-test%2F@8207f35cfcbec10afe4d5009faac659ba1bf9d8a