Security-flagged skill
This skill may contain destructive commands. Do not install, copy, download, or run it before reviewing the skill details and source. Use it deliberately and only in contexts you understand.
Scanner findings
highcredential_theft
Multi-file
analysisOfficial
Official Provider SkillView repo
Use when analysing, triaging, reporting on, or writing up what a WordPress sample did after it was offered in KadathSandbox at /Users/fioa8c/WORK/KadathSandbox — reading the run's Xdebug traces, Snuffleupagus log, decrypted flows, DNS, drop log, and database changes into a report with IOCs and a draft YARA rule. Follows kadath-offer.
Files4 files
SKILL.md71 lines
Loading editor…
Install
RecommendedOne command — your agent picks it up automatically.
Select an AI agent above to see the install command.
or
Manual Install
More stepsDownload the archive and add the files to your project manually.
Skill details
Versionv1.0.0
AuthorAutomattic
Categoryanalysis
Skill IDAutomattic/KadathSandbox/.claude/skills/kadath-scry
Files4 files
Related skills
Kadath GauntUse when you need OS-level evidence — syscalls, spawned processes with argv, file opens, raw connect() calls — from a WordPress sample running in KadathSandbox at /Users/fioa8c/WORK/KadathSandbox, rather than PHP-level Xdebug traces. Covers attaching strace and bpftrace to php-fpm via the tracer sidecar during a trigger.Kadath OfferUse when offering, running, executing, or "seeing what it does" for an untrusted WordPress plugin, theme, webshell, dropper, or loose PHP sample in the KadathSandbox sandbox at /Users/fioa8c/WORK/KadathSandbox — staging the sample, triggering it so its behaviour is traced, and marking the run so the artifacts can be attributed to it. Hands off to kadath-scry for the report.Kadath WardUse when operating, starting, resetting, snapshotting, self-testing, or troubleshooting the KadathSandbox WordPress malware sandbox at /Users/fioa8c/WORK/KadathSandbox — bringing the stack up, fixing a failing self-test or a container that will not come healthy, and understanding the containment model so you never weaken it to make a sample run.Dashboard Create ScreenCreate a new screen in the Multi-site Dashboard with automatic route registrationSelf Approve PrCheck whether a Pocket Casts Android pull request qualifies for self-approval and, if it does, label it "[Review] Self Approved". Use this whenever the user asks if they can self-approve, self-review, or merge their own PR without a human reviewer, or asks to "self-approve this PR". Pass a PR number as an argument, or run it from a branch with an open PR. Pass "check" to report the verdict without labelling.PrMUST be invoked before creating any PR, pushing a branch for review, or running `gh pr create`. Covers changelog entries, branch naming, PHPCS/PHPUnit checks, and reviewer assignment.