wordpress-full-compromise

Fail

Audited by Socket on Jul 31, 2026

2 alerts found:

MalwareSecurity
MalwareHIGH
references/mailinator-reset-workflow.md

This fragment is a highly actionable account-takeover workflow for WordPress: it registers an attacker-controlled user, intercepts the password reset email via Mailinator APIs, extracts the reset token from the email body, completes the WordPress reset process (including required cookies), sets an attacker-chosen password, and verifies access via XML-RPC. The behavior strongly indicates malicious intent and would be considered critical security risk if present in a package or repository.

Confidence: 95%Severity: 100%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and does not show malware-like install, exfiltration, or credential-harvesting behavior, but it is an offensive security skill that equips an AI agent to validate WordPress compromise chains up to admin/server control. High operational risk, low evidence of malicious intent.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fwordpress-full-compromise%2F@311cdd42dc8a5d0deec88cda7fd850678226509cd0a0b51a14a5f5e4259f80a9
Security Audit — socket — wordpress-full-compromise