indirect-syscall-dev
Audited by Socket on Sep 5, 2026
4 alerts found:
SecurityMalwarex3SUSPICIOUS. The main issue is not malware delivery but that the skill’s stated purpose is offensive EDR-evasion and syscall-stealth development for an AI agent. No credible remote installer or credential-exfil path is shown, and the pre-execution finding looks false positive, but the capability itself is a high-risk security/exploit tool inappropriate for broad agent use.
This code fragment is best characterized as a high-risk Windows direct-syscall dispatcher with deliberate EDR/AV evasion characteristics. It performs PEB-based ntdll export enumeration, builds seeded hash→SSN resolution, discovers a `syscall; ret` gadget in ntdll by opcode matching, and executes it via cross-language assembly trampolines that reorder ABI/stack arguments. The included gate-variant concepts and identifier hashing strongly indicate malicious intent or malware-enabling functionality. It should be treated as extremely dangerous and not used in production without a strong, verifiable legitimate purpose and independent review.
High-risk offensive syscall-evasion dispatcher. The code’s design centers on avoiding user-mode hooks by resolving SSNs from ntdll exports at runtime, caching a syscall;ret gadget via in-memory byte-pattern scanning, and invoking syscalls indirectly using hashed/obfuscated API identifiers. Explicit hook-drift/module revalidation further indicates intent to defeat EDR instrumentation rather than provide benign OS abstraction.
This module provides example patterns for a Windows NT syscall dispatcher explicitly designed for defense-evasion/stealth operation: it supports runtime mode switching between direct function-pointer calls and indirect syscall stubs, includes optional stack spoofing, and outlines low-level syscall gate validation/caching. Even though the file is presented as examples/documentation and omits full resolver/stack-spoof implementation, the core mechanisms described strongly align with malicious/offensive tradecraft (high-risk execution model) and present a significant supply-chain security concern for any dependency consumers.