weevely3
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS. The install source is broadly consistent with the upstream project, so this is not confirmed malware or a fake installer. However, the skill's actual footprint is fundamentally misaligned with its stated 'artifact analysis/containment' purpose: it instructs the agent to generate and upload an obfuscated PHP web shell, execute commands on remote hosts, read and exfiltrate files, scan internal networks, and create proxy/reverse-shell pivots. That offensive post-exploitation capability is disproportionate for an analysis skill and makes the skill high risk even without obvious credential theft.
The fragment is an offensive post-compromise operations guide centered on web-shell exploitation, credential/file theft, internal reconnaissance, privilege escalation, lateral movement, and backdoor or reverse-shell access. It is not obfuscated, but its stated behavior is strongly consistent with malicious or unauthorized use. The assessment applies to the supplied documentation; no package implementation was provided.