recon-smb-services
Audited by Socket on Jul 9, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS/HIGH-RISK skill. Its footprint is fundamentally offensive: targeted recon of weak SMB sites, extraction of PII/secrets, and explicit attack-chain development. No malicious installer is present, so this is not confirmed malware, but it is a high-risk exploit-oriented AI skill with disproportionate data-harvesting behavior.
The provided fragment is overwhelmingly offensive: it contains a credentialed browser “data exfiltration” PoC (using fetch with credentials:'include' and DOM output), plus automated recon/exploitation sequences targeting WordPress/WooCommerce CORS/XML-RPC behavior and probing common secret/source/config paths. There is no defensive or legitimate software logic in the fragment; it functions as an actionable attack playbook. If distributed via a dependency/repository, it would represent a serious security/supply-chain risk.