competition-ssrf-metadata-pivot

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK but not confirmed malware. The skill is internally coherent for a CTF SSRF workflow, yet its actual purpose is to equip an AI agent with offensive security guidance around metadata pivots and credential replay, which is inherently high risk. No direct exfiltration, hidden execution, or credential-harvesting endpoint is present in the provided text.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Jul 30, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Fai-fullstack-delivery-workflow%2Fcompetition-ssrf-metadata-pivot%2F@9ac0bec9149d609a68c409920e5879aff14405076920c943ed0b98f15bb823e4
Security Audit — socket — competition-ssrf-metadata-pivot