ctf-web
Audited by Socket on Sep 15, 2026
6 alerts found:
Securityx2Malwarex2Anomalyx2SUSPICIOUS. The skill is internally aligned with its stated CTF-web purpose, and most installs are from expected sources, so it is not disguised malware. However, its actual footprint is a high-risk offensive capability pack for an AI agent: exploit execution, exfiltration, prompt-jailbreak guidance, and system-prompt extraction instructions. This makes it unsafe for general agent deployment even though the behavior is coherent with CTF use.
This code fragment is an active web fuzzing/exploitation toolkit (Intruder/Reclab-like): it reads wordlists from disk, transforms payloads through a rule engine, injects them into HTTP requests, evaluates responses for likely ‘hits’, can spray headers/params with cookies/JWTs, and supports out-of-band callback detection via collaborator-style subdomain injection and polling. While it does not obviously contain stealthy backdoor logic (no process/file/secret exfiltration from the running host is shown), it is highly actionable offensive tooling, making it a substantial supply-chain security risk due to straightforward repurposing for unauthorized scanning/exploitation.
The provided code fragment is highly indicative of malicious exploit tooling. It uses SSRF to smuggle raw TCP via gopher, performs time-based blind SQL injection against an internal MySQL service, and reconstructs a secret (flag) by measuring induced delays from SLEEP(3). This is not consistent with legitimate supply-chain dependency behavior and presents a critical security risk if present in a published package.
The fragment is a CTF/web-attack writeup containing explicit XSS, cookie-exfiltration, and admin-bot compromise payload examples (including `document.cookie` exfil, webhook beacons, and `javascript:` scheme execution). It does not appear to be executable library code implementing these behaviors, so direct evidence of an actual malicious package behavior is limited. If this content were distributed inside a dependency, it would be highly suspicious, but based only on this fragment it reads primarily as instructional material rather than an active sabotage implementation.
The fragment is strongly indicative of an exploit/abuse pattern: it injects CRLF-delimited extra HTTP headers and even a second raw HTTP request into the SoapClient user_agent, then triggers transmission via __soapCall. While it does not show broader malware behavior (persistence/exfiltration), it is a high-risk network-layer attack primitive and should be treated as dangerous if it exists in any dependency or is reachable from untrusted input.
This code is best characterized as a dual-use web fuzzing/scanning utility. It actively generates URLs from a local wordlist and injects them into a user-supplied FUZZ-template URL, then performs concurrent HTTP GET requests and flags “hits” using response heuristics and optional grep/regex matching. There is no clear malware behavior in this fragment (no persistence, credential theft, stealth, or data exfiltration). The main security concerns are: (1) high operational abuse potential (automated probing) and (2) weakened TLS safety due to verify=False (especially in the async/httpx path) plus optional proxying, which can enable interception/MITM. Regex features introduce potential ReDoS/availability risk when regex patterns are poorly formed.