wpscan

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a WPScan reference, and the tool provenance appears legitimate, but its actual function is to equip an AI agent with offensive security capabilities including enumeration, brute-force attacks, authenticated scanning, and optional TLS bypass. That makes it high risk even without evidence of hidden exfiltration or malicious supply-chain behavior.

Confidence: 93%Severity: 90%
SecurityMEDIUM
references/wordpress-testing.md

The fragment is an offensive WordPress security-testing guide. It documents credential brute forcing, SSRF-based port probing, sensitive-file discovery, vulnerability exploitation, and post-authentication remote command execution. It is not itself malware or an installable package payload, and no obfuscated malicious code or embedded credentials are present. Use only with explicit authorization; the documented commands can compromise WordPress sites and expose credentials or internal services.

Confidence: 99%Severity: 90%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fwpscan%2F@a379006310a258ee962b40d97aa208ccd743de72213a215fa3ef59bf3283bcbd
Security Audit — socket — wpscan