misc-ctf
Audited by Socket on Sep 15, 2026
3 alerts found:
Securityx2MalwareSUSPICIOUS: the skill is internally coherent as an offensive CTF methodology, but it gives an AI agent broad exploit, privesc, secret-access, and network-action guidance and instructs loading additional offensive skills. Install trust is mostly normal documentation-level risk, and the pre-execution hits look non-executable, so this is not confirmed malware; it is high-risk offensive enablement.
No actual dependency/module code is present in the provided fragment; it is CTF-style exploit guidance for jail escape, privilege/internal service discovery, sensitive target access, and data exfiltration (notably via LD_PRELOAD-style injection and bash /dev/tcp). While this does not confirm supply-chain malware behavior in a package, the content is highly actionable for unauthorized intrusion and is a serious red flag if included in a distributable dependency artifact. If additional package files/scripts exist, they should be reviewed for real execution paths (postinstall scripts, binary launchers, embedded payloads, or suspicious use of LD_PRELOAD / /dev/tcp).
No dependency/library implementation was provided—only offensive exploitation/credential-theft/privilege-escalation instructions and command snippets. This prevents true source-to-sink analysis of a package module, but the fragment is strongly consistent with malicious/weaponized content. For supply-chain security, treat the overall artifact as highly suspicious pending inspection of the real packaged source, entrypoints, lifecycle scripts (install/postinstall), and any binaries/embedded payloads.