ctf-flag-hunting
Warn
Audited by Socket on May 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as a CTF post-exploitation guide, but its actual purpose is to help an AI agent perform offensive flag-hunting after compromise by harvesting files, credentials, process data, and database contents. There is little supply-chain risk, but the operational capability is high-risk offensive security tooling for an AI agent.
Confidence: 94%Severity: 90%
Audit Metadata