merlin

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent with Merlin’s upstream functionality, but that functionality is an AI-operated offensive C2 framework with covert transport, remote command execution, file transfer, and credential-dumping. Official GitHub sourcing lowers pure malware confidence, yet the skill remains high security risk because it equips an agent to conduct post-exploitation actions on remote systems.

Confidence: 95%Severity: 93%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:27 PM
Package URL
pkg:socket/skills-sh/AeonDave%2Fmalskill%2Fmerlin%2F@1e71be37a478394bcd8856494c8b0279729e7015
Security Audit — socket — merlin