shellter

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill’s behavior is coherent with its stated purpose, but that stated purpose is offensive malware deployment: backdooring legitimate executables for AV evasion and initial access. The install path is somewhat verifiable as official, yet the skill should still be treated as high risk because it gives an AI agent explicit exploit/malware-enablement capability.

Confidence: 91%Severity: 93%
Audit Metadata
Analyzed At
Apr 9, 2026, 06:13 PM
Package URL
pkg:socket/skills-sh/killvxk%2Fmalskills-zh%2Fshellter%2F@ec758f21cc50e0fa71d53d13bcc2321bf9772225