ctf-osint

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a CTF OSINT guide, but it gives an AI agent offensive intelligence-gathering capability over untrusted web content with bash and file-write access, and it includes one cleartext HTTP data flow. This looks more like a high-risk security skill than malware or credential theft.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 17, 2026, 11:23 PM
Package URL
pkg:socket/skills-sh/ljagiello%2Fctf-skills%2Fctf-osint%2F@67b04b9aadee55f8be4b7d09ad42b4af12d801a8