weevely3

Fail

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install source is broadly consistent with the upstream project, so this is not confirmed malware or a fake installer. However, the skill's actual footprint is fundamentally misaligned with its stated 'artifact analysis/containment' purpose: it instructs the agent to generate and upload an obfuscated PHP web shell, execute commands on remote hosts, read and exfiltrate files, scan internal networks, and create proxy/reverse-shell pivots. That offensive post-exploitation capability is disproportionate for an analysis skill and makes the skill high risk even without obvious credential theft.

Confidence: 94%Severity: 82%
MalwareHIGH
references/module-playbooks.md

The fragment is an offensive post-compromise operations guide centered on web-shell exploitation, credential/file theft, internal reconnaissance, privilege escalation, lateral movement, and backdoor or reverse-shell access. It is not obfuscated, but its stated behavior is strongly consistent with malicious or unauthorized use. The assessment applies to the supplied documentation; no package implementation was provided.

Confidence: 99%Severity: 97%
Audit Metadata
Analyzed At
Sep 15, 2026, 10:00 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fweevely3%2F@fad93dcd128d7026360bf9127a00879bf3375207bd097b3663ab14ebf01d7aa1
Security Audit — socket — weevely3