c-bof
Fail
Audited by Snyk on Apr 16, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). The GitHub link points to a Cobalt Strike BOF template — legitimate GitHub hosting but explicitly offensive/dual‑use tooling that can be used to build malware — and the second entry is an invalid placeholder URL, so together they warrant caution as a moderate‑to‑high risk source for malicious artifacts.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This content is an explicit, ready-to-use toolkit for building Cobalt Strike BOFs and includes process injection, remote thread creation, privilege escalation, credential-access/keylogging patterns, encrypted embedded payload execution, persistence (key/value store), and exfiltration IPC patterns—capabilities that enable unauthorized remote code execution, data theft, and backdoors.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill gives detailed, actionable code and patterns for process injection, privilege escalation (SeDebugPrivilege), process suspension/resume, keylogging, remote code execution and persistent payloads—explicitly instructing behaviors that modify and compromise the host system state.
Issues (3)
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata