deobfuscating-powershell-obfuscated-malware

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities fit its stated malware-analysis purpose, but it is still a high-risk AI-agent skill because it teaches offensive/security analysis workflows and executes transformed PowerShell locally with weakened policy controls. Install trust is also inconsistent due to mixed third-party tool provenance, especially the unclear PSDecode reference. No strong evidence of credential theft or covert exfiltration is present, so this is better classified as a risky security/exploit skill than as malware.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Apr 7, 2026, 06:48 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fdeobfuscating-powershell-obfuscated-malware%2F@74d438b6cdf5d70933900e4714b5b8a2ce07845c