winpeas
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill’s core purpose matches a real offensive security tool, but its footprint is high risk for an AI agent. The main issue is the explicit arbitrary HTTP remote-script execution pattern plus guidance to collect credentials and progress to active privilege-escalation exploits; this is too dangerous to treat as a benign helper even if official WinPEAS sources exist.
This is offensive Windows privilege-escalation guidance containing actionable instructions for service hijacking, DLL hijacking, registry abuse, reverse shells, and evasion. It is high-risk content if used operationally, but the supplied fragment is documentation only and does not itself execute malware or perform network, filesystem, or registry actions.