competition-web-runtime

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a CTF sandbox web-runtime guide, but it gives an AI agent offensive security capabilities and routes to multiple exploit-focused subskills. There is little supply-chain risk here, yet the overall security risk is high because the skill meaningfully enables web attack analysis, target probing, and processing of untrusted live content.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 31, 2026, 12:16 PM
Package URL
pkg:socket/skills-sh/GALIAIS%2FCTF-Sandbox-Orchestrator%2Fcompetition-web-runtime%2F@34181aef5298c51e4086252fb1b945259a4c9570