executing-phishing-simulation-campaign

Warn

Audited by Socket on Aug 27, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its footprint matches its stated purpose, but that purpose is to let an AI agent perform offensive phishing operations with real-world consequences, including credential harvesting and email delivery. Not confirmed malware, but it materially increases abuse, exfiltration, and operational risk.

Confidence: 91%Severity: 93%
SecurityMEDIUM
scripts/agent.py

The code provides legitimate GoPhish campaign-management functionality but includes inherently sensitive phishing capabilities, especially credential/password capture and campaign launching. It does not show independent malware behavior or covert exfiltration; network communication is directed to the user-supplied GoPhish server. Disabling TLS verification and ignoring SMTP certificate errors are significant security weaknesses. Use should be restricted to authorized simulations, with credential capture disabled where unnecessary and certificate verification enabled.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Aug 27, 2026, 07:37 AM
Package URL
pkg:socket/skills-sh/galyarderlabs%2Fgalyarder-framework%2Fexecuting-phishing-simulation-campaign%2F@b355cfe2d2a3b8673b74c784ae4dd94352f0210af40d44c33406924e364e4d6b
Security Audit — socket — executing-phishing-simulation-campaign