cloud-ctf

Warn

Audited by Socket on Sep 5, 2026

3 alerts found:

Securityx3
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an offensive cloud CTF guide, but its actual footprint is high risk for an AI agent: it operationalizes credential theft, metadata-token harvesting, privilege escalation, remote execution, and installs third-party tools. The main concern is not mismatch with purpose but that the purpose itself grants offensive capabilities inappropriate for broad agent use.

Confidence: 94%Severity: 91%
SecurityMEDIUM
references/iam-escalation-and-ssrf-chains.md

No executable malware is present in the provided fragment; it is a highly actionable offensive cheat sheet/playbook describing how to perform SSRF-to-IMDS credential harvesting, IAM privilege escalation, and subsequent pivots to access sensitive data across AWS/GCP/Azure. As a dependency content artifact, the primary supply-chain concern is misuse enablement (credential theft/tradecraft), not runtime compromise by embedded code.

Confidence: 82%Severity: 88%
SecurityMEDIUM
references/gcp-service-cheatsheet.md

No evidence of hidden malware or obfuscation is present in this fragment, and it is not a software dependency implementation. However, it contains highly actionable attack workflows for credential/secret abuse and privilege escalation in GCP (IMDS token theft, Secret Manager retrieval, Firestore full-data dumping to stdout, TOTP generation from recovered seeds, and GCE metadata injection to install SSH keys and obtain privileged access). Treat this content as dangerous when used outside authorized testing; it should not be included in production or distributed to untrusted parties.

Confidence: 70%Severity: 92%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:42 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fcloud-ctf%2F@4a060a3778cf479db9a551fbe46ef68b003d097f6ca1512fe05c5291bfd932c5
Security Audit — socket — cloud-ctf