indirect-syscall-dev

Fail

Audited by Socket on Sep 5, 2026

4 alerts found:

SecurityMalwarex3
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The main issue is not malware delivery but that the skill’s stated purpose is offensive EDR-evasion and syscall-stealth development for an AI agent. No credible remote installer or credential-exfil path is shown, and the pre-execution finding looks false positive, but the capability itself is a high-risk security/exploit tool inappropriate for broad agent use.

Confidence: 91%Severity: 88%
MalwareHIGH
references/lang-c-rust-go.md

This code fragment is best characterized as a high-risk Windows direct-syscall dispatcher with deliberate EDR/AV evasion characteristics. It performs PEB-based ntdll export enumeration, builds seeded hash→SSN resolution, discovers a `syscall; ret` gadget in ntdll by opcode matching, and executes it via cross-language assembly trampolines that reorder ABI/stack arguments. The included gate-variant concepts and identifier hashing strongly indicate malicious intent or malware-enabling functionality. It should be treated as extremely dangerous and not used in production without a strong, verifiable legitimate purpose and independent review.

Confidence: 86%Severity: 92%
MalwareHIGH
references/strategies.md

High-risk offensive syscall-evasion dispatcher. The code’s design centers on avoiding user-mode hooks by resolving SSNs from ntdll exports at runtime, caching a syscall;ret gadget via in-memory byte-pattern scanning, and invoking syscalls indirectly using hashed/obfuscated API identifiers. Explicit hook-drift/module revalidation further indicates intent to defeat EDR instrumentation rather than provide benign OS abstraction.

Confidence: 90%Severity: 95%
MalwareHIGH
references/implementation-examples.md

This module provides example patterns for a Windows NT syscall dispatcher explicitly designed for defense-evasion/stealth operation: it supports runtime mode switching between direct function-pointer calls and indirect syscall stubs, includes optional stack spoofing, and outlines low-level syscall gate validation/caching. Even though the file is presented as examples/documentation and omits full resolver/stack-spoof implementation, the core mechanisms described strongly align with malicious/offensive tradecraft (high-risk execution model) and present a significant supply-chain security concern for any dependency consumers.

Confidence: 66%Severity: 88%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:42 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Findirect-syscall-dev%2F@63b794c3da6d2f65fee0d20552ccab67ec1a260f5c56b785bf034f949a88cf43
Security Audit — socket — indirect-syscall-dev