competition-web-runtime

Warn

Audited by Socket on Jul 30, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent for a CTF sandbox web-analysis role, but it is an offensive-security skill that inspects sensitive browser/session data and processes untrusted external content. There is no direct malware or exfiltration behavior in the text, and no explicit installer, but the broader skill-family provenance is only partially verifiable from third-party mirrors and linked sibling skills increase transitive trust risk.

Confidence: 81%Severity: 72%
SecurityMEDIUM
references/cookie-hmac-key-reuse-auth-bypass.md

This fragment is not a software supply-chain dependency implementation; it is an explicit, actionable exploitation write-up/code sample for a web authentication/authorization bypass caused by HMAC key reuse and server trust of cookie payload claims. If such a vulnerable design exists in a target system, the steps materially enable privilege escalation (admin cookie forgery) with no obfuscation. For supply-chain security assessment, it indicates high risk as offensive content, not as evidence of malicious behavior in a packaged open-source component.

Confidence: 62%Severity: 85%
Audit Metadata
Analyzed At
Jul 30, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Fai-fullstack-delivery-workflow%2Fcompetition-web-runtime%2F@446f3fd11013d75c9aa5c76c9f38878e4e7e1d15549f883196c1998c3e10bfe1
Security Audit — socket — competition-web-runtime