liffy
Audited by Socket on Sep 5, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS. The install path is moderately trustworthy because it points to a real same-project GitHub repo with source, but it still clones and executes unpinned code without verification. More importantly, the skill’s actual function is offensive exploitation: it equips an AI agent to perform LFI/path traversal testing and potential RCE techniques against targets, which is high risk even if not credential-stealing malware.
This fragment is an explicit offensive exploitation cheat-sheet for LFI, log poisoning, wrapper abuse, traversal bypasses, and sensitive file targets, including a payload that embeds PHP command execution (system($_GET['cmd'])) in a data:// wrapper scenario. While it is not executable code by itself, it strongly indicates malicious intent and would be security-relevant if distributed within a dependency because it meaningfully supports real-world exploitation when paired with an LFI weakness.