ctf-web

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a CTF web exploitation guide, and its installs mostly use legitimate sources, but it is high risk because it equips an AI agent with offensive security capabilities, arbitrary target interaction, and exploit execution workflows. This is not clear malware or credential theft, but it is an unsafe skill to grant to a general-purpose agent.

Confidence: 94%Severity: 86%
Audit Metadata
Analyzed At
Apr 17, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/ljagiello%2Fctf-skills%2Fctf-web%2F@db7affdfa0f8523188a938b48ca639fe4aae8f04