osint-ctf

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill broadly enables OSINT plus offensive-recon techniques, and it can route user-provided tokens to external services. Data flows mostly go to official/public endpoints and the only explicit installer is an official documented package, so this is not confirmed malware; however, the scope is somewhat disproportionate for a generic OSINT skill because it mixes passive research with active recon tooling and token-based API enumeration.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fosint-ctf%2F@0698b37705baa661839744ff0b1693941c37ecbf6abe664693ec441fba79396f
Security Audit — socket — osint-ctf