phishing-technique
Audited by Socket on Sep 5, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: the skill’s footprint is coherent with its stated purpose, but that purpose is to equip an AI agent with phishing and AitM offensive capability. There is no clear malware payload or hidden exfiltration endpoint in the skill text, yet it meaningfully increases real-world attack capacity and supports credential and session capture workflows.
The provided artifact is not a software module; it is highly actionable offensive guidance for phishing and credential/session interception (AitM with Evilginx/GoPhish concepts, OAuth device-code token theft, BitB overlays, QR lures, Teams/Slack pivoting, and clickfix paste-and-run execution). There is no code logic to trace, but the described flows and operational integration details strongly indicate malicious purpose. If this content appears in a dependency package, it represents a serious security risk and potential supply-chain compromise indicator focused on enabling account takeover and token/session theft.