recon-smb-services

Fail

Audited by Socket on Jul 9, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its footprint is fundamentally offensive: targeted recon of weak SMB sites, extraction of PII/secrets, and explicit attack-chain development. No malicious installer is present, so this is not confirmed malware, but it is a high-risk exploit-oriented AI skill with disproportionate data-harvesting behavior.

Confidence: 95%Severity: 91%
MalwareHIGH
references/wave9-pattern-catalog.md

The provided fragment is overwhelmingly offensive: it contains a credentialed browser “data exfiltration” PoC (using fetch with credentials:'include' and DOM output), plus automated recon/exploitation sequences targeting WordPress/WooCommerce CORS/XML-RPC behavior and probing common secret/source/config paths. There is no defensive or legitimate software logic in the fragment; it functions as an actionable attack playbook. If distributed via a dependency/repository, it would represent a serious security/supply-chain risk.

Confidence: 82%Severity: 100%
Audit Metadata
Analyzed At
Jul 9, 2026, 05:22 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Frecon-smb-services%2F@18d4f7ed6db30e9fa34212623a4d80b81c87b8e37b99c67387f54a9c14c1a475
Security Audit — socket — recon-smb-services