ctf-reverse

Warn

Audited by Socket on Sep 15, 2026

3 alerts found:

Securityx3
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned as a CTF reverse-engineering guide, and most data flows/install sources are coherent with that purpose. However, it equips an AI agent with high-risk offensive RE capabilities and many executable, unpinned third-party install paths, including source builds and curl|bash patterns, making it risky even without clear credential theft or malicious exfiltration.

Confidence: 90%Severity: 74%
SecurityMEDIUM
anti-analysis.md

Overall, the fragment is strongly characteristic of anti-analysis/anti-debug and anti-VM evasion logic, with self-integrity checks and described exception-driven code mutation (mprotect + patching) that would substantially hinder reverse engineering and dynamic instrumentation. No explicit exfiltration or credential theft mechanisms are shown in this excerpt, but the behavioral profile (termination on detection, instrumentation resistance, and potential hidden logic activation) is high-risk for a supply-chain dependency. Treat as suspicious until the exact compiled source and runtime effects of the specific module are confirmed.

Confidence: 42%Severity: 72%
SecurityMEDIUM
tools-advanced-2.md

Overall, this fragment is high-risk dual-use offensive material. It contains explicit capability-enabling patterns for remote code execution (curl→bash) and for dumping execute-only mapped executable code via an LD_PRELOAD constructor (/proc/self/mem → /tmp). While it does not show direct exfiltration or persistence, its concrete mechanisms and patching primitives make it unsuitable to trust as a normal dependency without strong provenance and validation of actual packaged code vs. pasted notes.

Confidence: 70%Severity: 82%
Audit Metadata
Analyzed At
Sep 15, 2026, 05:39 AM
Package URL
pkg:socket/skills-sh/ljagiello%2Fctf-skills%2Fctf-reverse%2F@825db7b70e5f6b3d78d200d1f5f09b1be0836b52b7104a89c921de9f873f4472
Security Audit — socket — ctf-reverse