wordpress-penetration-testing

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. The content is internally consistent with its stated purpose, and referenced tools are legitimate, but that purpose is to give an AI agent offensive security capabilities: scanning, credential attacks, exploitation, and shell access against WordPress targets. No clear publisher-side credential harvesting or hidden exfiltration is present, but the autonomous attack guidance, reverse-shell payloads, and TLS-check disabling make the skill dangerous and inappropriate for general agent use.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
Sep 15, 2026, 04:33 PM
Package URL
pkg:socket/skills-sh/zebbern%2Fclaude-code-guide%2Fwordpress-penetration-testing%2F@589a7f540ab06fb9d8fdf8f045c4744254aee4177ff68f076baa4520dac937a5
Security Audit — socket — wordpress-penetration-testing