watson

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches the documented capability, but the skill depends on an external Watson.exe binary with no install path, version pinning, checksum, or official release verification in the skill. There is no clear credential theft or exfiltration, but the binary trust gap and offensive exploit-selection guidance make the skill high risk relative to a normal documentation-only skill.

Confidence: 90%Severity: 78%
MalwareHIGH
references/patching-workflow.md

The provided fragment is highly malicious offensive material. It provides an actionable end-to-end workflow to identify missing Windows security patches, map them to specific high-impact CVEs, execute weaponized exploitation steps to gain SYSTEM/domain control, then dump credentials (LSASS/Mimikatz) and support lateral movement, with added OPSEC/evasion guidance. There are no benign defensive or auditing-only characteristics in the content. If any such material were included in an open-source dependency or build artifact, it would represent a severe supply-chain security threat.

Confidence: 82%Severity: 100%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fwatson%2F@333d8486ef727599e283ceae93d0a0d716318d93ed3c469512f43268ad44865e
Security Audit — socket — watson