performing-phishing-simulation-with-gophish

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
references/api-reference.md

The fragment serves as a legitimate tooling reference for conducting phishing simulations via the GoPhish API. It does not itself execute malicious code but introduces capabilities that could be misused for credential harvesting if deployed without proper controls. Security posture should emphasize authorization, consent, access controls, logging, and secure handling of credentials and collected data during campaigns.

Confidence: 59%Severity: 65%
Audit Metadata
Analyzed At
Apr 7, 2026, 01:01 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-phishing-simulation-with-gophish%2F@c0540e8c08b335968e62779b74875b0664a7c921