wpscan
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS. The skill is internally coherent as a WPScan reference, and the tool provenance appears legitimate, but its actual function is to equip an AI agent with offensive security capabilities including enumeration, brute-force attacks, authenticated scanning, and optional TLS bypass. That makes it high risk even without evidence of hidden exfiltration or malicious supply-chain behavior.
The fragment is an offensive WordPress security-testing guide. It documents credential brute forcing, SSRF-based port probing, sensitive-file discovery, vulnerability exploitation, and post-authentication remote command execution. It is not itself malware or an installable package payload, and no obfuscated malicious code or embedded credentials are present. Use only with explicit authorization; the documented commands can compromise WordPress sites and expose credentials or internal services.