asm-testing
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The flagged command-injection pattern is benign documentation, but the overall skill gives an AI agent offensive security and live process instrumentation capabilities that go beyond routine software development. There is no obvious credential theft, exfiltration, or malicious installer behavior, yet the skill materially increases the agent's ability to perform exploit-oriented debugging and reverse-engineering actions on local targets.
The fragment is a legitimate low-level assembly testing toolkit. Its shellcode loaders intentionally execute arbitrary file contents from RWX memory, and the trampoline validator can dereference arbitrary addresses; these are significant risks if used with untrusted inputs, but they are explicit test functionality rather than hidden malicious behavior. The fragment shows no credential theft, exfiltration, persistence, obfuscation, or destructive activity.