wordpress-full-compromise
Audited by Socket on Jul 31, 2026
2 alerts found:
MalwareSecurityThis fragment is a highly actionable account-takeover workflow for WordPress: it registers an attacker-controlled user, intercepts the password reset email via Mailinator APIs, extracts the reset token from the email body, completes the WordPress reset process (including required cookies), sets an attacker-chosen password, and verifies access via XML-RPC. The behavior strongly indicates malicious intent and would be considered critical security risk if present in a package or repository.
SUSPICIOUS. The skill is internally coherent and does not show malware-like install, exfiltration, or credential-harvesting behavior, but it is an offensive security skill that equips an AI agent to validate WordPress compromise chains up to admin/server control. High operational risk, low evidence of malicious intent.