competition-graphql-rpc-drift

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能不是明显恶意或凭据窃取型内容,但它明确为CTF/沙箱中的GraphQL/RPC契约漂移与隐藏操作分析提供进攻性安全能力,属于高风险安全研究技能。未见外部安装、凭据转发或异常数据外流;主要风险来自其可被AI代理用于发现和复现实战化接口偏差。

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 31, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/GALIAIS%2FCTF-Sandbox-Orchestrator%2Fcompetition-graphql-rpc-drift%2F@e523e04e7f4bf866cdf986814685ab765ec8f4c1