payload-crafter

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. It is internally consistent as a pentest payload library, but that stated purpose is itself an offensive-security capability for AI agents, including exploit payload generation and OOB verification guidance. There is little evidence of malware or deceptive install behavior, but the skill materially increases offensive capability and references callback infrastructure commonly used for exfiltration-style verification.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
May 18, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/roodlicht%2Faccans-sec-skills%2Fpayload-crafter%2F@4e110f370fb3ea225fd1cb8628751e0410e0b681
Security Audit — socket — payload-crafter