beef
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS. The install path is largely consistent with the stated publisher and official docs, but the skill’s stated purpose is itself offensive: it enables browser hooking, phishing, persistence, cookie theft, and MITM-assisted injection. This belongs to a penetration-testing framework, but as an AI agent skill it grants high-risk offensive capability with real exfiltration impact, so overall risk is high even without evidence of hidden malware.
The supplied material is documentation for a dual-use browser exploitation and command-and-control framework. It explicitly describes highly dangerous capabilities, including credential harvesting, session-cookie theft, keylogging, surveillance, persistence, internal network reconnaissance, browser exploitation, and Metasploit payload execution. The examples also contain insecure default or hardcoded credentials and token transmission through URLs. Because no executable package code is provided, malware attribution is limited; however, the documented functionality presents a high security risk if used outside an authorized testing environment.