fsop-dev

Warn

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent and not deceptive about its purpose, but that purpose is to help an AI agent perform offensive binary-exploitation research and build FSOP exploit chains. There is little supply-chain or credential risk in the provided files, yet the capability itself is high-risk because it equips the agent with practical exploitation guidance.

Confidence: 95%Severity: 87%
AnomalyLOW
references/triggers-and-call-paths.md

This fragment is exploit-development guidance for glibc FSOP, describing concrete corruption of FILE internals to obtain arbitrary read/write and potential indirect control-flow to RCE. There is no actual dependency implementation shown, so runtime malicious behavior cannot be verified from this snippet alone; however, the content is highly actionable and offensive in nature. If found within a package’s source or distribution artifacts, it should be treated as a strong supply-chain security red flag pending investigation of surrounding files and how/if it is executed.

Confidence: 55%Severity: 65%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:40 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Ffsop-dev%2F@6e742cb9472ba5b90a07222e4de84f9d48b5ff2c3d44d076e62460ef4c599547
Security Audit — socket — fsop-dev