fsop-dev
Audited by Socket on Sep 5, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The skill is coherent and not deceptive about its purpose, but that purpose is to help an AI agent perform offensive binary-exploitation research and build FSOP exploit chains. There is little supply-chain or credential risk in the provided files, yet the capability itself is high-risk because it equips the agent with practical exploitation guidance.
This fragment is exploit-development guidance for glibc FSOP, describing concrete corruption of FILE internals to obtain arbitrary read/write and potential indirect control-flow to RCE. There is no actual dependency implementation shown, so runtime malicious behavior cannot be verified from this snippet alone; however, the content is highly actionable and offensive in nature. If found within a package’s source or distribution artifacts, it should be treated as a strong supply-chain security red flag pending investigation of surrounding files and how/if it is executed.