edr-evasion-dev

Fail

Audited by Socket on Sep 5, 2026

7 alerts found:

SecurityMalwarex6
SecurityMEDIUM
SKILL.md

SUSPICIOUS: this skill is an offensive EDR-evasion and process-injection playbook for loaders/implants, giving an AI agent high-risk security/stealth capabilities with real-world abuse potential. I found no strong supply-chain abuse, but the skill’s core function is incompatible with benign agent assistance and squarely fits high-risk offensive security tooling.

Confidence: 94%Severity: 90%
MalwareHIGH
references/process-injection.md

This fragment is not a functional dependency; it is explicit malware tradecraft documentation for Windows injection/evasion techniques (remote memory write/execution, APC/thread hijacking, PPID spoofing, threadless DLL/EPI execution, and thread-pool callback hijacking). No actual executable logic is present here, but the intent and specificity indicate malicious operational guidance. If this appears inside a published package, it is a serious supply-chain red flag.

Confidence: 83%Severity: 80%
MalwareHIGH
references/linux-edr-evasion.md

This fragment is an explicitly adversarial Linux EDR/XDR evasion and intrusion playbook. It provides actionable reconnaissance-to-action guidance to fingerprint eBPF/LSM/kprobe coverage and then execute stealthy fileless/in-memory execution, exploit io_uring observability gaps, interfere with security telemetry (including competing BPF/map manipulation and LKM/ftrace concepts), establish persistence, perform injection, and enable covert C2. Treat it as a strong supply-chain compromise indicator and a malicious operational artifact rather than benign documentation.

Confidence: 90%Severity: 100%
MalwareHIGH
references/constraints.md

The provided content is not actual compilable library code; it is a highly specific adversary/operator memo describing Windows in-memory payload loading, process injection, syscall/VEH/ETW evasion, ntdll unhooking, and anti-analysis behaviors. These are strong malware indicators typical of offensive implants. Because the real implementation is not present in the excerpt, the analysis cannot confirm concrete data flows or exact code paths, but the described capabilities are critically concerning for any supply-chain dependency that contains or implements this behavior.

Confidence: 40%Severity: 90%
MalwareHIGH
references/best-practices.md

This fragment is not a benign dependency module; it is adversarial doctrine for building and operating stealthy loader/implant tooling that targets EDR/telemetry evasion on Windows and Linux, including staged enablement, signature minimization, and anti-analysis/testing guidance. Although the excerpt contains no executable logic, its explicit malicious operational intent and detailed capability-oriented instructions make the supply-chain risk high.

Confidence: 80%Severity: 95%
MalwareHIGH
references/anti-analysis.md

This fragment is high-risk attacker tradecraft guidance for anti-debug/anti-VM evasion and stealth execution. It specifies how to detect analysis environments, selectively trigger evasive branching, conceal static indicators (IAT/API/string hiding and late binding), and manipulate entropy/section placement to reduce ML/AV detection. No direct malicious execution is shown here, but the intent and techniques are strongly consistent with malware/loader development. Additional code context would be required to confirm that the referenced behaviors are actually implemented in the package.

Confidence: 78%Severity: 85%
MalwareHIGH
references/etw-patching.md

This fragment describes a high-risk ETW-evading loader technique: temporary byte-stomping of ntdll’s NtTraceEvent and EtwEventWrite prologues using NtWriteVirtualMemory (self-target) to suppress telemetry during a short window, then restoring original bytes to evade integrity checks before handoff to longer execution. While actual implementational details are not present, the described intent and concrete patch-and-restore workflow are strongly consistent with malicious staging/stealth behavior.

Confidence: 82%Severity: 90%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:42 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fedr-evasion-dev%2F@c6c649ec9686bd0a1fff8e7d954d0f80b94087dbd1f65bc4270042d9610c6a38
Security Audit — socket — edr-evasion-dev