detecting-rootkit-activity
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is internally coherent for malware/rootkit forensics and shows no credential theft or exfiltration path, but it materially expands an AI agent’s offensive/advanced security-analysis capability and references powerful external tools without tightly scoped install guidance. Main risk is capability class, not hidden malicious behavior.
Confidence: 89%Severity: 64%
Audit Metadata