ctf-ai-ml

Warn

Audited by Socket on Mar 28, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: internally consistent as a CTF attack reference, but it is an offensive security skill that equips an agent to perform AI/ML and LLM attack techniques against targets. Install trust is mostly normal package-manager use; the main concern is the exploit-oriented capability combined with Bash/Web access, not malware or covert exfiltration.

Confidence: 91%Severity: 78%
SecurityMEDIUM
model-attacks.md

No evidence of stealthy system compromise (no backdoors, process control, credential theft, or covert exfiltration) is present in this fragment. However, the file is a set of active ML attack scripts (inversion, extraction, membership inference, and weight/LoRA manipulation) that can be directly abused, and it includes high-risk deserialization via torch.load of .pt artifacts, which can enable arbitrary code execution if model files are untrusted or tampered. Treat as potentially dangerous offensive tooling rather than a safe library; do not ship or execute with untrusted checkpoints.

Confidence: 62%Severity: 71%
Audit Metadata
Analyzed At
Mar 28, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/ljagiello%2Fctf-skills%2Fctf-ai-ml%2F@3cc4fa775e07520805edfa1f0a02e6a5d65b917c