xmlrpc-exploitation

Fail

Audited by Socket on Jul 31, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS: this skill is purpose-built to let an AI agent attack WordPress targets through XML-RPC abuse, including credential attacks, SSRF validation through an exfiltration service, and webshell-based RCE. There is no unusual installer risk, but the operational behavior itself is high-risk and incompatible with a benign agent skill.

Confidence: 98%Severity: 98%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fxmlrpc-exploitation%2F@55b0b7dd4b5242c8a5ab7fe8f38bb71489bdbcde5598dc212d2e4328aa24f7f8
Security Audit — socket — xmlrpc-exploitation