competition-cloud-metadata-path

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for a CTF/sandbox metadata-escalation purpose, but that purpose itself gives an AI agent offensive security guidance for SSRF-to-metadata and metadata-to-privilege escalation. There are no install or credential-forwarding indicators in the provided text, so this is not confirmed malware, but it is a high-risk security skill whose safety depends heavily on the upstream sandbox controls that are not shown.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 31, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/GALIAIS%2FCTF-Sandbox-Orchestrator%2Fcompetition-cloud-metadata-path%2F@52709d30ea89dc908999f7b3dea2c7ee7be5f967