wp-plugin-automation

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its red-team purpose, but that purpose is to give an AI agent offensive security capability for bulk external WordPress vulnerability discovery and PoC generation. No strong credential theft or malicious exfiltration is shown, yet the scalable exploit workflow and disabled TLS checks make it high security risk.

Confidence: 94%Severity: 90%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fwp-plugin-automation%2F@98192fdbdf244a1005ff384937ef773466c9765c81d7853a0821007d7e07e9ac
Security Audit — socket — wp-plugin-automation