shellcode-fluctuation
Fail
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone an external GitHub repository (
github.com/mgeeky/ShellcodeFluctuation) which contains specialized code for security software evasion. This source is not affiliated with the skill author or a trusted organization list. - [COMMAND_EXECUTION]: Provides explicit shell commands for cloning repositories and compiling C++ source code using MSVC and MinGW (
x86_64-w64-mingw32-g++). These commands are intended to create a binary (fluctuator.exe) that manipulates system memory protections. - [REMOTE_CODE_EXECUTION]: The core purpose of the skill is to facilitate the execution of arbitrary shellcode while evading detection. It provides technical patterns for XOR-encrypting payloads in memory and dynamically switching memory page permissions (e.g., from Read-Execute to Read-Write) to defeat memory scanners. It further suggests integration with offensive tools like Cobalt Strike and the use of indirect syscalls to bypass operating system API hooks.
Recommendations
- AI detected serious security threats
Audit Metadata