avira-security-loader-2026-deployment
Warn
Audited by Socket on Aug 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is plausible, but the actual footprint depends on downloading and executing an unverifiable Windows executable from an unrelated personal GitHub Pages site rather than an official Avira-owned source. The skill also elevates privileges, creates SYSTEM persistence, and supports credentialed remote deployment, making the scope disproportionate and the supply-chain risk high.
Confidence: 94%Severity: 95%
Audit Metadata