phpsploit

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an offensive post-exploitation framework, but that purpose itself is high risk for an AI agent because it enables webshell deployment, stealthy command execution, file transfer, and exploit plugins. The install instructions are also inconsistent with the upstream project's official distribution path, increasing trust concerns. Not confirmed malware, but clearly a high-risk offensive security skill.

Confidence: 95%Severity: 91%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/AeonDave%2Fmalskill%2Fphpsploit%2F@5c3fd265e07569dbcc1a3d017999e2860d30d433
Security Audit — socket — phpsploit