sliver

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is an offensive C2 framework for implant deployment, remote command execution, file transfer, and traffic pivoting. Publisher/install provenance appears legitimate and same-org, so this is not disguised malware, but it is a high-risk capability set that should not be granted to a general AI agent without strict containment and human approval.

Confidence: 95%Severity: 93%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/AeonDave%2Fmalskill%2Fsliver%2F@f3a8d3c1e8993928e0837c497dcb88f73f761150
Security Audit — socket — sliver