shellcode-dev

Fail

Audited by Socket on Sep 5, 2026

5 alerts found:

Securityx3MalwareAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: no malicious installer, credential theft, or hidden exfiltration is present, and the scanner finding is a false positive. However, the skill is fundamentally an offensive shellcode-development and payload-loader guide for AI-agent use, enabling exploit-adjacent code generation and runtime validation, so its overall security risk is high even though malware likelihood is low.

Confidence: 92%Severity: 84%
SecurityMEDIUM
references/loader-core-qualification.md

The fragment is highly suspicious: it describes a manual-mapped in-memory payload execution qualification workflow with direct control transfer into decoded code, randomized execution addresses, strict failure handling, and low-level `ntdll`/`Zw*` syscall stub steering. While the provided snippet contains no direct evidence of exfiltration or credential theft and does not include actual executable implementation, its content strongly matches offensive loader/implant guidance. Treat the surrounding package as high-risk and require inspection of the full source (entrypoints, build/install scripts, binary blobs, dynamic download/exec, and any loader-like code).

Confidence: 62%Severity: 78%
SecurityMEDIUM
references/evasion-patterns-from-projects.md

No executable code is provided, so this fragment alone cannot demonstrate data theft, remote command execution, or other concrete malicious behavior. However, it explicitly documents multiple malware-loader/evasion techniques (dynamic syscall indirection, gadget selection, stack spoofing prerequisites, sleep masking, reflective in-memory loading, and mitigation-aware gadget handling), which is a strong contextual indicator of potentially malicious intent within the broader project. Treat the package as high review priority and verify the actual shipped executable/runtime components.

Confidence: 72%Severity: 70%
MalwareHIGH
references/platform-workflows.md

This fragment is highly consistent with instructions for building a cross-platform in-memory payload loader/shellcode executor (PIC + syscall/ABI correctness). It describes an end-to-end execution pipeline—allocate memory, copy/decode attacker-controlled bytes, mark memory executable (RX/RWX), and transfer control to the decoded code—along with detailed guidance to make it work reliably across OS/architectures. Even without explicit exfiltration/persistence details, the described capability is strongly indicative of malware/dropper functionality and should be treated as high risk in a software supply-chain context.

Confidence: 74%Severity: 85%
AnomalyLOW
references/encoders-and-stagers.md

This module is non-executable instructional documentation about building staged/encoded payload delivery mechanisms with validation and evasion considerations. It contains no direct malicious behavior, but the explicit emphasis on stagers, decoder mechanics, and polymorphic/metamorphic evasion is a notable offensive-tooling signal. Investigate the surrounding repository context and whether any actual encoder/stager implementation exists elsewhere; based on this fragment alone, danger is limited to contextual/suspicion risk rather than confirmed runtime compromise.

Confidence: 62%Severity: 48%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:41 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fshellcode-dev%2F@1e1680f3a56cba27879dd8f28111c981ca1bed17f64687a8d13c6758e2ee8a12
Security Audit — socket — shellcode-dev