unauthorized-access-common-services
Audited by Socket on Apr 10, 2026
2 alerts found:
Securityx2This fragment functions as an offensive exploitation cheat sheet rather than benign software code. It contains concrete, copy-pastable instructions for enumeration, brute force, server-side command execution, webshell/WAR payload deployment, and lateral-movement-style operations across many network services. As shipped content in a supply chain, it would significantly raise misuse impact, even though it does not appear to be executable malware itself in this snippet.
The skill directly instructs theft of remote files, SSH key planting, rsync looting, webshell deployment, and reverse-shell callbacks. These outbound flows are central to the skill's purpose and clearly enable unauthorized data access and exfiltration.