rag-exploitation

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This code is an offensive, dual-use toolkit for testing and executing RAG attacks (KB poisoning, retrieval manipulation, context injection, embedding collision). It contains deliberate obfuscation and persistence mechanisms (zero-width hiding, vectorstore.add) and provides actionable, stepwise methods that materially lower the barrier to abuse. Acceptable only in tightly controlled, authorized red-team/test environments with strict access controls, content validation, and audit logging. In untrusted or production contexts where ingestion and indexing controls are lax, treat as high risk and remove or restrict.

Confidence: 90%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:59 AM
Package URL
pkg:socket/skills-sh/pluginagentmarketplace%2Fcustom-plugin-ai-red-teaming%2Frag-exploitation%2F@abe93267c2afebcb60f1ab94389e63866830346d