liffy

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install path is moderately trustworthy because it points to a real same-project GitHub repo with source, but it still clones and executes unpinned code without verification. More importantly, the skill’s actual function is offensive exploitation: it equips an AI agent to perform LFI/path traversal testing and potential RCE techniques against targets, which is high risk even if not credential-stealing malware.

Confidence: 92%Severity: 78%
MalwareHIGH
references/lfi-techniques.md

This fragment is an explicit offensive exploitation cheat-sheet for LFI, log poisoning, wrapper abuse, traversal bypasses, and sensitive file targets, including a payload that embeds PHP command execution (system($_GET['cmd'])) in a data:// wrapper scenario. While it is not executable code by itself, it strongly indicates malicious intent and would be security-relevant if distributed within a dependency because it meaningfully supports real-world exploitation when paired with an LFI weakness.

Confidence: 78%Severity: 85%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fliffy%2F@1b40ac9ae518e9215c3c83d21885d539ab3ac8e10a4cd26e81f706f0f2fb5d97
Security Audit — socket — liffy