ctf-misc

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a CTF exploitation reference, and its installs/data flows mostly use normal sources and official endpoints. However, it grants an AI agent broad offensive-security capability—privesc, escapes, RCE, tokenized API actions, and filesystem/network access—so the overall security risk is high even without clear malware or credential-harvesting behavior.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
Apr 17, 2026, 10:35 PM
Package URL
pkg:socket/skills-sh/ljagiello%2Fctf-skills%2Fctf-misc%2F@30a832db8ac05291885a9ac1d90930a40ed0cbdf