ctf-web-methodology

Fail

Audited by Socket on Apr 22, 2026

3 alerts found:

AnomalySecurityMalware
AnomalyLOW
references/server-side-exec.md

The fragment functions as a high-level reference of server-side exploitation techniques rather than an executable exploit. It poses a notable risk if misused or redistributed without safeguards, but it does not contain runnable malware. Properly packaged with warnings, mitigations, and access controls, it can support defensive learning without enabling harm.

Confidence: 59%Severity: 60%
SecurityMEDIUM
SKILL.md

该技能不是普通开发/文档技能,而是专门让 AI 代理执行 CTF/Web 漏洞侦察与利用的方法论。未见明显恶意植入、凭据窃取或可疑供应链行为,但其能力范围本身属于高风险攻防用途,和“让代理具备渗透/利用能力”高度一致,应归类为高风险、可疑的攻击型技能而非恶意软件。

Confidence: 93%Severity: 83%
MalwareHIGH
references/flag-extraction.md

This fragment is high-risk misuse content: it provides step-by-step instructions to locate and extract secrets/flags after achieving RCE in a container, and it describes multiple exfiltration paths (web-root file write, outbound HTTP/DNS callbacks, and timing side-channel leakage). It does not appear to be benign dependency code, but instead an attacker runbook; treat any inclusion in a distributed package as a security red flag requiring removal and provenance review.

Confidence: 72%Severity: 74%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fctf-web-methodology%2F@f8944052a29a3273874f1140c099c87c7bac8995
Security Audit — socket — ctf-web-methodology