crypto-ctf

Fail

Audited by Socket on Sep 5, 2026

3 alerts found:

Securityx2Malware
SecurityMEDIUM
SKILL.md

This skill is not malware, but it is a high-risk offensive-security skill for an AI agent. Its capabilities are internally consistent with a crypto CTF/lab purpose, and the flagged install/pre-execution items mostly read as documentation artifacts; the main risk is that it teaches practical cryptanalytic and exploit workflows that could be redirected beyond CTF use.

Confidence: 89%Severity: 79%
SecurityMEDIUM
references/prng.md

This excerpt does not appear to be a normal library implementation; it is an exploit/cryptanalysis write-up focused on recovering PRNG state/seeds from externally exposed values to predict security-sensitive tokens and break encryption/authorization flows (notably password reset/session/CSRF-like artifacts). No direct evidence of system compromise (exfiltration/persistence/backdoor execution) is present in the provided snippet, but the content’s explicit, operational intent makes it a serious supply-chain red flag if included in a dependency package. A full review of the entire repository/package (entrypoints, install scripts, runtime code, network/file/process usage) is required to confirm whether it is merely documentation or embedded into executable logic.

Confidence: 62%Severity: 72%
MalwareHIGH
references/modern-cipher-modes-and-forgery.md

The provided code fragment is exploit-oriented cryptographic attack logic targeting AES-CBC encryption used for authorization cookies/tokens without integrity protection. It demonstrates (1) decryption-oracle-style verification via plaintext validity/known plaintext comparisons to recover missing key material/IV, and (2) CBC ciphertext byte-flipping to deterministically alter a specific authorization field (admin) to escalate privileges. No stealth, persistence, or exfiltration mechanics are shown in the snippet, but the intent and operations are strongly malicious with high security impact against improperly secured cookie/token designs.

Confidence: 70%Severity: 90%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fcrypto-ctf%2F@add8c0dd4368faa9b313c35d0c4511b52f58100c895a3e27a9efbb0d337df09f
Security Audit — socket — crypto-ctf