implementing-siem-use-cases-for-detection

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is purpose-aligned for detection engineering, but it materially increases risk by instructing an AI agent to install a remote PowerShell framework and execute Atomic Red Team attack simulations. The install path appears official and not credential-harvesting, so this is not confirmed malware; however, the combination of remote-script execution and offensive security capability makes the skill suspicious/high-risk for agent use.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 20, 2026, 11:34 PM
Package URL
pkg:socket/skills-sh/mukul975%2Fanthropic-cybersecurity-skills%2Fimplementing-siem-use-cases-for-detection%2F@9ba62d211652cbab01fbce5d60ab240450481512