extracting-config-from-agent-tesla-rat

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, and the provided code stays local, but it equips an AI agent with explicit malware reverse-engineering and credential-extraction functionality for a RAT family. There is no clear credential theft or exfiltration by the skill itself, so this is not confirmed malware; the main issue is high-risk offensive security capability plus optional third-party sandbox data exposure.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fextracting-config-from-agent-tesla-rat%2F@bc8f0ac826fa947f9d4856ad1a5271509749336c