merlin
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is coherent with Merlin’s upstream functionality, but that functionality is an AI-operated offensive C2 framework with covert transport, remote command execution, file transfer, and credential-dumping. Official GitHub sourcing lowers pure malware confidence, yet the skill remains high security risk because it equips an agent to conduct post-exploitation actions on remote systems.
Confidence: 95%Severity: 93%
Audit Metadata