upload-insecure-files
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. This skill is internally consistent as an upload-exploitation playbook, but its actual purpose is to give an AI agent offensive security capabilities against target systems, including upload-to-RCE chains and linked exploit pivots. No direct credential theft, hidden execution, or malicious installer is present, so it is not confirmed malware, but it is a high-risk offensive skill.
Confidence: 94%Severity: 86%
Audit Metadata