operating-sliver-c2
Audited by Socket on Aug 7, 2026
2 alerts found:
SecurityMalwareHigh-risk offensive security skill. The install path is mostly coherent and same-project official, so this is not confirmed malware, but the skill’s actual footprint is a full AI-operable C2/post-exploitation capability with implant generation, credential access, stealth guidance, and lateral movement. That makes it dangerous and disproportionate for general agent use.
This module is a high-risk, capability-rich CLI wrapper for Sliver C2: it can connect to a C2 backend, generate implant payload binaries from operator-supplied parameters, write the resulting binaries to disk, and execute arbitrary commands on existing remote sessions while printing results. While the code is not obfuscated, its functional behavior aligns directly with malware/C2 tooling, making it a severe supply-chain security concern if distributed without strict provenance and access controls.