evil-winrm

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its stated purpose is offensive remote access and post-exploitation on Windows hosts. It gives an AI agent high-risk capabilities including credentialed remote execution, file transfer, pass-the-hash/ticket workflows, AMSI bypass, and in-memory payload loading; this is not covert malware, but it is a high-risk offensive-security skill.

Confidence: 94%Severity: 92%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:57 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fevil-winrm%2F@cad453290587d04e024b94cfd4b148724ec8a98d208895b7a913c89ffcac55e6
Security Audit — socket — evil-winrm