ctf-solve

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent and uses normal tooling for its stated CTF purpose, but that purpose is to give an AI agent offensive security and exploitation capability, including interaction with arbitrary remote services and routing into pwn/web/malware workflows. No clear credential theft, exfiltration, obfuscation, or malicious install chain is present.

Confidence: 93%Severity: 74%
Audit Metadata
Analyzed At
Mar 27, 2026, 12:28 PM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fctf-solve%2F@4972a4f9a6282052bbbbb4ea367f2bab86e3853d