skills/aeondave/malskill/cpp-bof/Gen Agent Trust Hub

cpp-bof

Warn

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a shell script (scripts/build_bof.sh) that executes the x86_64-w64-mingw32-g++ compiler and strip utility to generate binary objects from source code.
  • Evidence: The script scripts/build_bof.sh uses $CC and x86_64-w64-mingw32-strip to compile and process output files.
  • [DATA_EXFILTRATION]: The skill includes documentation and code implementations for exfiltrating sensitive data, such as screen captures and local files, over an established command-and-control (C2) Beacon channel.
  • Evidence: SKILL.md and references/REFERENCE.md describe using CALLBACK_FILE, CALLBACK_FILE_WRITE, and CALLBACK_SCREENSHOT to transmit data back to an operator.
  • [REMOTE_CODE_EXECUTION]: The skill is designed to produce Beacon Object Files (BOFs), which are executable code blocks that run in the memory space of a remote process via an external loader.
  • Evidence: The core purpose of the skill is the generation of COFF (Common Object File Format) objects specifically for injection and execution in remote environments via Cobalt Strike.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — cpp-bof