web-security

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This file is an explicit offensive web-exploitation guide suitable for CTFs and authorized penetration testing. It contains legitimate tool references and operational steps for active exploitation. There is no direct evidence of obfuscation, embedded malware, or hard-coded malicious endpoints, but because it instructs and normalizes intrusive operations and grants shell/write capabilities, it poses a meaningful misuse risk if used against unauthorized targets. Restrict use to authorized environments, add safeguards (consent checks, logging), and consider removing or gating powerful capabilities (Bash, Write) in automated contexts.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 17, 2026, 07:21 AM
Package URL
pkg:socket/skills-sh/kiwamizamurai%2Fcctf%2Fweb-security%2F@9838f4e5dbd4628475157dcb0946c64675ac8350