executing-phishing-simulation-campaign
Audited by Socket on Aug 27, 2026
2 alerts found:
Securityx2SUSPICIOUS/HIGH-RISK skill. Its footprint matches its stated purpose, but that purpose is to let an AI agent perform offensive phishing operations with real-world consequences, including credential harvesting and email delivery. Not confirmed malware, but it materially increases abuse, exfiltration, and operational risk.
The code provides legitimate GoPhish campaign-management functionality but includes inherently sensitive phishing capabilities, especially credential/password capture and campaign launching. It does not show independent malware behavior or covert exfiltration; network communication is directed to the user-supplied GoPhish server. Disabling TLS verification and ignoring SMTP certificate errors are significant security weaknesses. Use should be restricted to authorized simulations, with credential capture disabled where unnecessary and certificate verification enabled.