performing-aws-privilege-escalation-assessment

Fail

Audited by Socket on Mar 15, 2026

2 alerts found:

SecurityObfuscated File
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for an AWS privilege-escalation assessment, but it gives an AI agent offensive cloud-exploitation capability with real-world impact and forwards AWS credentials to multiple external tools. There is no clear exfiltration or credential-harvesting behavior, so this is not confirmed malware; the main concerns are offensive-agent enablement and moderate supply-chain trust from third-party tool installs.

Confidence: 90%Severity: 81%
Obfuscated FileHIGH
references/api-reference.md

This is a high-value offensive/defensive reference describing precise IAM/STS API calls and tools that enable privilege escalation and persistence in AWS accounts. While not malicious code by itself, it is highly actionable: with valid credentials it provides a clear roadmap for compromising AWS privileges. Use only in authorized testing with proper approvals and monitoring; defenders should use the document to hunt for the listed misuse patterns and harden IAM policies, enable logging/alerts, and enforce least privilege.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 15, 2026, 09:41 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-aws-privilege-escalation-assessment%2F@ecc011ac94afa80f00e4e55028dacd0359b7981b