bettercap
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill’s stated purpose is offensive network attack tooling, and its actual instructions center on credential capture, MITM interception, DNS spoofing, SSL stripping, JS injection, and deauthentication. Install provenance for Bettercap itself appears official and same-project, so this is not primarily a supply-chain issue; the risk comes from giving an AI agent explicit exploit and data-harvesting capabilities with real-world impact.
This is an offensive-tool reference document rather than malicious executable code. It contains no direct file execution, persistence, credential exfiltration, or embedded malware payload in the supplied text. However, the documented commands enable active man-in-the-middle attacks, credential interception, traffic manipulation, Wi-Fi password cracking, device disruption, and BLE modification. Use is appropriate only with explicit authorization, and default API credentials must be changed or the API must remain strictly local.