skills/mukul975/anthropic-cybersecurity-skills/conducting-cloud-infrastructure-penetration-test/Socket
conducting-cloud-infrastructure-penetration-test
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s behavior matches its stated pentest purpose, but that purpose is itself high risk: it gives an AI agent offensive cloud-security capabilities, direct credential handling, metadata-token extraction, and exploit/backdoor workflows. Install provenance is mostly legitimate, yet the overall skill should be treated as high risk due to offensive use, credential forwarding, and real-world cloud actions.
Confidence: 95%Severity: 91%
Audit Metadata