competition-web-runtime
Audited by Socket on Jul 30, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill is coherent for a CTF sandbox web-analysis role, but it is an offensive-security skill that inspects sensitive browser/session data and processes untrusted external content. There is no direct malware or exfiltration behavior in the text, and no explicit installer, but the broader skill-family provenance is only partially verifiable from third-party mirrors and linked sibling skills increase transitive trust risk.
This fragment is not a software supply-chain dependency implementation; it is an explicit, actionable exploitation write-up/code sample for a web authentication/authorization bypass caused by HMAC key reuse and server trust of cookie payload claims. If such a vulnerable design exists in a target system, the steps materially enable privilege escalation (admin cookie forgery) with no obfuscation. For supply-chain security assessment, it indicates high risk as offensive content, not as evidence of malicious behavior in a packaged open-source component.