performing-threat-emulation-with-atomic-red-team

Warn

Audited by Socket on Mar 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent for threat-emulation, but it gives an AI agent explicit offensive security execution capability and depends on a third-party attack-execution framework with optional remote credential use. No clear exfiltration or confirmed malware appears in the provided skill text, but the operational and security risk is high.

Confidence: 91%Severity: 81%
AnomalyLOW
references/api-reference.md

The code demonstrates threat-emulation tooling that can perform remote code execution and access credential-related utilities. While intended for controlled testing, these capabilities introduce significant risk if misused or exposed publicly. Strict controls, environment isolation, input whitelisting, signed atomics, and explicit user consent are essential to mitigate potential abuse and supply-chain risks.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:54 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-threat-emulation-with-atomic-red-team%2F@7ed0ff95b054319f227e687a34bc61da186f3068