wordpress-cors-xmlrpc-rce-chain
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent and avoids obvious credential theft or supply-chain abuse, but it is an offensive security skill that enables an AI agent to perform authorized exploit-chain validation, including upload and possible execution testing against WordPress targets. Risk is driven by agent-enabled attack capability, not by malicious data flow or installer behavior.
Confidence: 91%Severity: 76%
Audit Metadata