competition-malware-config

Warn

Audited by Socket on Jun 20, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md
AnomalyLOW
agents/openai.yaml

This fragment is not executable malware; it is a prompt/policy configuration that instructs an external orchestrator to recover hidden, staged, malware-like configuration elements (including bot IDs and beacon/C2 parameters) from a sample after another component is active. The wording is highly malware-adjacent, making it suspicious in context, but direct malicious behavior (networking, credential theft, payload execution) is not present in the provided code fragment. Security review should focus on the referenced orchestrator/tool implementation and where any recovered data is stored or transmitted.

Confidence: 72%Severity: 50%
Audit Metadata
Analyzed At
Jun 20, 2026, 03:16 AM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fcompetition-malware-config%2F@d7d4ee9f19962da8497a32a8f9ec69d76649d1b1288c0e3af0ea20bd843f5457
Security Audit — socket — competition-malware-config