ai-threat-testing
Audited by Socket on Apr 20, 2026
2 alerts found:
AnomalySecurityNo runnable code is provided in this fragment, so direct malware behavior cannot be confirmed. However, the content is an explicit adversarial testing/evasion and forensic-impairment playbook (including log/evidence manipulation tactics and “undetected attack” success criteria). This represents a meaningful supply-chain and misuse risk: the module appears designed to help bypass detection rather than to implement defensive monitoring.
SUSPICIOUS. The skill is internally consistent as an offensive AI pentesting framework, but it equips an AI agent with high-risk exploit and security testing capabilities against real targets. The main concern is not hidden exfiltration in the excerpt; it is that the skill enables autonomous offensive actions, system prompt extraction, model theft testing, privilege escalation, and logging bypass. Because this is a security/exploit tool for an AI agent, overall risk is high even without explicit malicious infrastructure.