hackthebox
Warn
Audited by Socket on May 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK. The skill is internally aligned with Hack The Box operations, but it equips an AI agent for offensive security, uses multi-agent automation, collects a wider-than-necessary secret set, and references Cloudflare bypass guidance. Official HTB/OpenVPN/Slack endpoints reduce outright malware certainty, yet the opaque local secret reader and `/skill-update` keep execution and data-flow trust unresolved.
Confidence: 92%Severity: 89%
Audit Metadata