ics-ctf

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the content is internally aligned with an ICS/OT CTF/offensive-lab purpose, but that purpose itself grants an AI agent broad exploit-style capabilities: protocol writes, MITM, credential harvesting from project/config files, AD/IT-to-OT pivots, and transitive skill loading. Static command-injection hits are mostly false positives from documentation, and there is no confirmed malware or hidden exfiltration endpoint, but the skill is high-risk because it operationalizes offensive security actions beyond cautious read-only analysis.

Confidence: 89%Severity: 78%
MalwareHIGH
references/attack-patterns.md

The provided fragment is highly actionable offensive guidance for OT/ICS sabotage and telemetry falsification. It includes concrete techniques to (1) inject false data via timed Modbus writes (FDI/race condition) and (2) perform L2 MITM with ARP spoof + NFQUEUE + scapy packet rewriting to alter Modbus responses in transit. It further provides pivot guidance to engineering workstations/HMIs/historians to obtain tag mappings and credentials that enable the attack workflow. There is no obfuscation, and the described misuse can directly impact operator-visible outcomes and process integrity.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fics-ctf%2F@4782634693374e9c7efe748ba73e2d2a1e4a07e97c609bb0dec150ed333fc734
Security Audit — socket — ics-ctf