kubernetes-pentesting

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s footprint matches its stated purpose, but that purpose is to give an AI agent offensive Kubernetes exploitation capability. It includes credential theft patterns, disabled TLS checks, privileged cluster actions, cloud token harvesting, and transitive loading of more attack skills. Not confirmed malware, but clearly a high-risk offensive security skill.

Confidence: 95%Severity: 95%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:15 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fkubernetes-pentesting%2F@2083193e04707de9f5841ceaf2b34a98dab65775