winpeas

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose matches a real offensive security tool, but its footprint is high risk for an AI agent. The main issue is the explicit arbitrary HTTP remote-script execution pattern plus guidance to collect credentials and progress to active privilege-escalation exploits; this is too dangerous to treat as a benign helper even if official WinPEAS sources exist.

Confidence: 93%Severity: 88%
SecurityMEDIUM
references/service-exploitation.md

This is offensive Windows privilege-escalation guidance containing actionable instructions for service hijacking, DLL hijacking, registry abuse, reverse shells, and evasion. It is high-risk content if used operationally, but the supplied fragment is documentation only and does not itself execute malware or perform network, filesystem, or registry actions.

Confidence: 99%Severity: 88%
Audit Metadata
Analyzed At
Sep 15, 2026, 10:05 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fwinpeas%2F@61347317233be37bdba844bd05273bb67f4d21b4a0ed38d6728389e8a9fec7f7
Security Audit — socket — winpeas