gdb
Audited by Socket on Sep 5, 2026
3 alerts found:
Securityx3SUSPICIOUS. The skill is internally coherent for a GDB malware-analysis/reverse-engineering guide, and its install sources are mostly official/same-project. Main concerns are the official-but-risky GEF curl-to-bash installer and the fact that this skill equips an AI agent with explicit exploit-research and malware-debugging capabilities, which makes the overall security risk high even without evidence of credential theft or covert exfiltration.
This fragment is dual-use malware-analysis tooling that explicitly enables anti-debug bypass (ptrace/SIGTRAP and /proc/self/status TracerPid manipulation, timing result tampering), plus unpacking-style extraction of executable memory regions and network/payload tracing with stdout logging. It does not itself show autonomous compromise, persistence, or outbound exfiltration, but it materially increases capability for evasion and code harvesting against anti-analysis defenses; therefore it should be treated as high operational risk if distributed or executed without strict purpose controls.
Overall, this is a dual-use GDB instrumentation script. The standout risk signal is the explicit ptrace anti-debug bypass (forcing $rax = 0) plus aggressive logging of network/process-execution-related data, including sampled send buffer contents, persisted to a predictable local file (/tmp/malware_trace.json). While it does not by itself perform remote exfiltration or system-level malware actions, it meaningfully defeats anti-analysis and can capture sensitive runtime data, making it security-relevant and potentially suspicious in a supply-chain context if delivered as part of a broader dependency.