xmlrpc-exploitation
Fail
Audited by Socket on Jul 31, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS: this skill is purpose-built to let an AI agent attack WordPress targets through XML-RPC abuse, including credential attacks, SSRF validation through an exfiltration service, and webshell-based RCE. There is no unusual installer risk, but the operational behavior itself is high-risk and incompatible with a benign agent skill.
Confidence: 98%Severity: 98%
Audit Metadata