ctf-flag-hunting

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a CTF post-exploitation guide, but its actual purpose is to help an AI agent perform offensive flag-hunting after compromise by harvesting files, credentials, process data, and database contents. There is little supply-chain risk, but the operational capability is high-risk offensive security tooling for an AI agent.

Confidence: 94%Severity: 90%
Audit Metadata
Analyzed At
May 4, 2026, 08:17 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fctf-flag-hunting%2F@64c655d8ab1f74ee950b46c896758857af54b3f7