This report does not block or authorize the manifest or ZIP.
The skill contains operational penetration testing instructions, including network scanning, Metasploit exploitation, credential attacks, persistence, privilege escalation checks, command injection examples, and destructive disk commands. Some keyword-only malware taxonomy and Markdown fence findings are false positives, but multiple confirmed critical findings remain. The skill should not be published until offensive and destructive procedures are removed or constrained to non-operational lab guidance.
Report position
Historical report
Open audit history before using this report to install.
Audit attestation
Not attestable
The required immutable binding is incomplete.
Human verification
Not verified
No human verification is recorded for this report.
Coverage
1 Files scanned · 467 Lines analyzed
68 items shown for review
Limitations
This report does not claim runtime or sandbox execution and does not prove the absence of side effects.
01
Evidence chain
Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.
The block walks through Metasploit exploitation using MS17-010 EternalBlue and a Meterpreter reverse TCP payload. This is operational exploit guidance.
The URL is a placeholder, but it is embedded in SQLMap commands that enumerate databases and tables. This is direct SQL injection exploitation guidance.
The URL is a placeholder, but it is embedded in SQLMap commands that enumerate databases and tables. This is direct SQL injection exploitation guidance.
The block instructs host discovery with Nmap and arp-scan against a network range. This can enumerate live systems on networks that may not be authorized.
The range introduces active exploitation and the Metasploit framework before the executable examples. The context is gaining access rather than defensive validation only.
The block provides WHOIS, DNS enumeration, dnsrecon, and email harvesting commands for target reconnaissance. These commands can collect target intelligence outside an approved scope.
The block gives Google dork queries for exposed files, login pages, directory listings, and environment files. This supports target reconnaissance and sensitive information discovery.
03
Risk findings
Confirmed security concerns are separated from items that still need review.
The Backdoors heading appears under Maintaining Access and introduces persistence examples. This is not only taxonomy; it frames backdoors as a testing step.
The line discusses cleaning up backdoors after testing, confirming that prior steps included backdoor placement. This keeps a high-risk persistence workflow in scope.
The troubleshooting section advises using a proxy or VPN and fragmenting packets when scans are blocked. This can help bypass defensive controls during unauthorized scanning.
The cited lines directly recommend tactics for continuing scans after blocking, including proxy or VPN use and packet fragmentation.
The common attack types section lists phishing, email-based credential theft, fake login pages, malicious attachments, and social engineering. It is brief, but the intent is credential theft education.
The text explicitly references phishing and credential theft, but it does not provide a full phishing kit or delivery procedure.
04
Remediation
Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.
FIX-001
Critical
Operational exploitation and persistence guidance
Remove Metasploit exploit steps, Meterpreter payloads, SSH key persistence, cron backdoors, and maintaining access instructions. Replace them with high-level defensive concepts.
FIX-002
Critical
Sensitive file and command injection examples
Remove payloads that access /etc/passwd or enumerate databases with SQLMap. Use benign toy examples without real system paths or data extraction.
FIX-003
Critical
Destructive device commands
Remove dd, gparted, mount, and raw /dev/sdb examples from the marketplace skill, or replace them with warnings and non-executable setup guidance.
FIX-004
High
Credential attack commands
Remove Hydra brute force examples and password cracking workflows, or restrict them to non-executable descriptions for isolated lab accounts.
FIX-005
High
Defense evasion troubleshooting
Remove advice to use proxies, VPNs, or packet fragmentation when scans are blocked. Replace it with scope review and authorization escalation steps.
05
Expert evidence
Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.
Artifact subject
Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable
Analysis metadata
Audit model: codex
Analysis state: Complete
Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.