extracting-config-from-agent-tesla-rat
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, and the provided code stays local, but it equips an AI agent with explicit malware reverse-engineering and credential-extraction functionality for a RAT family. There is no clear credential theft or exfiltration by the skill itself, so this is not confirmed malware; the main issue is high-risk offensive security capability plus optional third-party sandbox data exposure.
Confidence: 90%Severity: 74%
Audit Metadata