offensive-dependency-confusion
Deep-dive offensive methodology for dependency confusion and namespace attacks across all major package ecosystems. Covers npm scope confusion exploiting the gap between public and private scoped packages and .npmrc misconfigurations where registry mappings fail to pin internal scopes exclusively. Addresses PyPI namespace attacks through --extra-index-url resolution ordering, NuGet feed priority exploitation when multiple package sources are configured without clear directives, Maven and Gradle repository ordering where artifact resolution traverses repositories sequentially, Go module proxy abuse through GOPROXY misconfiguration, Ruby gems namespace squatting, and Docker image tag confusion with unqualified image references. . Use when performing authorized red-team, pentest, or research work involving dependency confusion.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-dependency-confusion/SKILL.md
- skills/offensive-dependency-confusion/LICENSE
- skills/offensive-dependency-confusion/README.md
- skills/offensive-dependency-confusion/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.