beef

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install path is largely consistent with the stated publisher and official docs, but the skill’s stated purpose is itself offensive: it enables browser hooking, phishing, persistence, cookie theft, and MITM-assisted injection. This belongs to a penetration-testing framework, but as an AI agent skill it grants high-risk offensive capability with real exfiltration impact, so overall risk is high even without evidence of hidden malware.

Confidence: 96%Severity: 91%
SecurityMEDIUM
references/modules.md

The supplied material is documentation for a dual-use browser exploitation and command-and-control framework. It explicitly describes highly dangerous capabilities, including credential harvesting, session-cookie theft, keylogging, surveillance, persistence, internal network reconnaissance, browser exploitation, and Metasploit payload execution. The examples also contain insecure default or hardcoded credentials and token transmission through URLs. Because no executable package code is provided, malware attribution is limited; however, the documented functionality presents a high security risk if used outside an authorized testing environment.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fbeef%2F@ddb881b0548e3669feb53f0a1fa2f4667654bb44745f63b2bd7f8bf223e44ade
Security Audit — socket — beef