kubernetes-pentesting

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its behavior matches the stated purpose, so it is not deceptive malware, but the purpose itself is an offensive attack playbook for an AI agent: secret extraction, token abuse, privileged pod creation, Kubelet/etcd access, cloud credential harvesting, and chaining into other offensive skills. No hidden installer or covert exfiltration is shown, but the skill materially enables penetration and post-exploitation actions against Kubernetes and cloud environments.

Confidence: 93%Severity: 86%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:15 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fkubernetes-pentesting%2F@a01125357fa6ae201cf5feca5268a1fb777dbd80685307f5b97701fa001ae2e5
Security Audit — socket — kubernetes-pentesting