competition-windows-pivot

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for a CTF Windows-pivot purpose and shows no direct exfiltration or installer abuse, but it gives an AI agent high-risk offensive-security guidance around credential material, replay, and privilege movement. The main concern is capability scope and transitive trust, not confirmed malware.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Jul 30, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Fai-fullstack-delivery-workflow%2Fcompetition-windows-pivot%2F@99f8cef53baddddb3020a38a300dc4bee81e616e790d15e1bb497d8fadfc032b
Security Audit — socket — competition-windows-pivot