xxd
Fail
Audited by Socket on Apr 20, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS. The skill’s stated purpose is itself decode-and-exec concealment, and its actual behavior is to hide a curl|sh payload from an unrelated HTTP domain. This is fundamentally incompatible with a legitimate helper skill and presents a high-likelihood remote code execution and potential payload delivery mechanism.
Confidence: 99%Severity: 99%
Audit Metadata