hackthebox

Warn

Audited by Socket on May 2, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. Parts of the workflow align with Hack The Box operations, but the skill is high risk because it equips an AI agent for offensive security tasks, aggregates multiple unrelated secrets through a local helper, enables autonomous multi-agent actions, and references Cloudflare bypass behavior. The HTB VPN download itself is consistent with official HTB usage, but the overall footprint exceeds a narrowly scoped platform helper.

Confidence: 91%Severity: 90%
SecurityMEDIUM
reference/cloudflare-bypass.md

No traditional malware is evident in this fragment, but it is highly actionable and purpose-built to circumvent Cloudflare bot protections (Turnstile) by evading automation signals, running headed-like automation via Xvfb/Playwright flags, and reusing clearance cookies (cf_clearance, __cf_bm). This represents a strong misuse and security-control circumvention risk; it should be treated as high-risk content if included in a software dependency or distributed to users.

Confidence: 80%Severity: 86%
Audit Metadata
Analyzed At
May 2, 2026, 01:02 AM
Package URL
pkg:socket/skills-sh/transilienceai%2Fcommunitytools%2Fhackthebox%2F@f5600b96bb563a0f3de529f7f22519b9b0ca41f1