detecting-rootkit-activity

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent for malware/rootkit forensics and shows no credential theft or exfiltration path, but it materially expands an AI agent’s offensive/advanced security-analysis capability and references powerful external tools without tightly scoped install guidance. Main risk is capability class, not hidden malicious behavior.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Apr 20, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/mukul975%2Fanthropic-cybersecurity-skills%2Fdetecting-rootkit-activity%2F@0d00178f98bfd64cce2843b6ba7ec8d26fae3e20