phishing-technique

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s footprint is coherent with its stated purpose, but that purpose is to equip an AI agent with phishing and AitM offensive capability. There is no clear malware payload or hidden exfiltration endpoint in the skill text, yet it meaningfully increases real-world attack capacity and supports credential and session capture workflows.

Confidence: 92%Severity: 90%
MalwareHIGH
references/modern-aitm-tradecraft.md

The provided artifact is not a software module; it is highly actionable offensive guidance for phishing and credential/session interception (AitM with Evilginx/GoPhish concepts, OAuth device-code token theft, BitB overlays, QR lures, Teams/Slack pivoting, and clickfix paste-and-run execution). There is no code logic to trace, but the described flows and operational integration details strongly indicate malicious purpose. If this content appears in a dependency package, it represents a serious security risk and potential supply-chain compromise indicator focused on enabling account takeover and token/session theft.

Confidence: 82%Severity: 98%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fphishing-technique%2F@281655fd47515784aed9aad546ae2874153f51d761dbbcd13d6acac59123e6fb
Security Audit — socket — phishing-technique