misc-ctf

Fail

Audited by Socket on Sep 15, 2026

3 alerts found:

Securityx2Malware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an offensive CTF methodology, but it gives an AI agent broad exploit, privesc, secret-access, and network-action guidance and instructs loading additional offensive skills. Install trust is mostly normal documentation-level risk, and the pre-execution hits look non-executable, so this is not confirmed malware; it is high-risk offensive enablement.

Confidence: 89%Severity: 74%
SecurityMEDIUM
references/bashjails.md

No actual dependency/module code is present in the provided fragment; it is CTF-style exploit guidance for jail escape, privilege/internal service discovery, sensitive target access, and data exfiltration (notably via LD_PRELOAD-style injection and bash /dev/tcp). While this does not confirm supply-chain malware behavior in a package, the content is highly actionable for unauthorized intrusion and is a serious red flag if included in a distributable dependency artifact. If additional package files/scripts exist, they should be reviewed for real execution paths (postinstall scripts, binary launchers, embedded payloads, or suspicious use of LD_PRELOAD / /dev/tcp).

Confidence: 62%Severity: 74%
MalwareHIGH
references/linux-privesc.md

No dependency/library implementation was provided—only offensive exploitation/credential-theft/privilege-escalation instructions and command snippets. This prevents true source-to-sink analysis of a package module, but the fragment is strongly consistent with malicious/weaponized content. For supply-chain security, treat the overall artifact as highly suspicious pending inspection of the real packaged source, entrypoints, lifecycle scripts (install/postinstall), and any binaries/embedded payloads.

Confidence: 60%Severity: 90%
Audit Metadata
Analyzed At
Sep 15, 2026, 10:00 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fmisc-ctf%2F@9e5677c04a96777bace9c0733cfea0cc4613de480de64ad77c56db40e2ed0976
Security Audit — socket — misc-ctf