winrm-pentesting

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is internally consistent with its stated purpose, but that purpose is offensive intrusion. It enables credential attacks, remote execution, lateral movement, relay abuse, and evasion on Windows hosts, making it a high-risk AI-agent capability. The external tools referenced appear legitimate, so this is not confirmed malware, but it is a dangerous security/exploit skill with substantial abuse potential.

Confidence: 94%Severity: 95%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fwinrm-pentesting%2F@9084925639c12287f01dbfc5196bde6e0531a38a249b9f35df2c11365280b00c
Security Audit — socket — winrm-pentesting