competition-windows-pivot

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a CTF sandbox Windows-pivot specialist, but it equips an AI agent to analyze and potentially operationalize credential replay, Kerberos delegation, and lateral movement using highly sensitive Windows secrets. No malware, covert exfiltration, or suspicious installer is present in this fragment, yet the offensive security capability makes the overall skill high-risk if used outside the claimed sandbox scope.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Mar 31, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/GALIAIS%2FCTF-Sandbox-Orchestrator%2Fcompetition-windows-pivot%2F@cdcdcd284335fc3860a779e06a60d4df60f53977