cpp-bof
Warn
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a shell script (
scripts/build_bof.sh) that executes thex86_64-w64-mingw32-g++compiler andstriputility to generate binary objects from source code. - Evidence: The script
scripts/build_bof.shuses$CCandx86_64-w64-mingw32-stripto compile and process output files. - [DATA_EXFILTRATION]: The skill includes documentation and code implementations for exfiltrating sensitive data, such as screen captures and local files, over an established command-and-control (C2) Beacon channel.
- Evidence:
SKILL.mdandreferences/REFERENCE.mddescribe usingCALLBACK_FILE,CALLBACK_FILE_WRITE, andCALLBACK_SCREENSHOTto transmit data back to an operator. - [REMOTE_CODE_EXECUTION]: The skill is designed to produce Beacon Object Files (BOFs), which are executable code blocks that run in the memory space of a remote process via an external loader.
- Evidence: The core purpose of the skill is the generation of COFF (Common Object File Format) objects specifically for injection and execution in remote environments via Cobalt Strike.
Audit Metadata