investigating-phishing-email-incident
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities largely match its stated SOC phishing-investigation purpose, and network endpoints are mostly official or expected security vendors. Risk comes from third-party detonation/data sharing and the inclusion of high-impact containment actions that could purge mail or reset accounts if executed autonomously; this is a high-risk operational skill, not confirmed malware.
Confidence: 89%Severity: 66%
Audit Metadata