tplmap
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive SSTI exploitation, RCE, shell, and file-transfer capabilities. Supply-chain trust is only moderate due to direct install from a personal, stale GitHub repo and metadata inconsistencies, but the main concern is the high-risk offensive capability rather than confirmed malware or credential theft.
Confidence: 93%Severity: 90%
Audit Metadata