commix
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2The skill is internally consistent with its stated purpose, but that purpose is an offensive exploitation workflow for AI agents. No deceptive installer, credential harvesting, or third-party exfiltration is shown, and the static findings are documentation false positives; however, the skill materially enables command injection exploitation, shell access, file exfiltration from targets, and payload upload, making it high security risk even without confirmed malware intent.
The provided material is an offensive command-injection and post-exploitation playbook. It contains explicit reverse-shell, webshell, exfiltration, WAF-bypass, and privilege-enumeration instructions. It does not constitute package malware by itself because no executable package code or installation behavior is supplied, but the commands can enable unauthorized access and data theft when applied to vulnerable systems.