pyexfil

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose and capabilities are internally consistent, and the install source appears to match the upstream project, but the skill is explicitly an offensive exfiltration toolkit for covert data transfer. Giving an AI agent turnkey data-exfil channels is disproportionate and dangerous even without clear malware indicators.

Confidence: 95%Severity: 94%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/AeonDave%2Fmalskill%2Fpyexfil%2F@ffa20657736d63aef52dd3fa3be8e2c82ba82eef
Security Audit — socket — pyexfil