WordPress Penetration Testing

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill, not confirmed malware. Its capabilities are internally consistent with its stated purpose, and the named tools are official/publicly sourced, but the purpose itself is offensive: it enables enumeration, credential attacks, exploitation, shell upload, and evasion. No hidden third-party exfiltration path is evident, yet the skill materially increases misuse risk and includes disabled TLS examples and credential-forwarding to external tools/targets.

Confidence: 93%Severity: 88%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:23 AM
Package URL
pkg:socket/skills-sh/googyosoo%2Fantigravity-skills%2Fwordpress-penetration-testing%2F@d36fe284f355c8716e4d1cd1c2b07899684ce77a
Security Audit — socket — WordPress Penetration Testing