stack-spoofing-dev

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the scanner hits are mostly false positives, but the skill’s actual purpose is to help an AI agent implement offensive stack-spoofing and EDR-evasion techniques. Its capabilities align with that stated purpose, yet that purpose is itself high risk for an agent skill because it enables stealthy security tradecraft and syscall obfuscation.

Confidence: 93%Severity: 84%
MalwareHIGH
references/lang-c-rust-go.md

High likelihood of malicious/offensive intent: the provided assembly constructs fake stack frames and performs indirect calls to a syscall gadget to spoof execution/call origin. This is a well-known evasion technique used in malware. In a dependency ecosystem, such code represents a serious supply-chain risk because it can execute sensitive syscalls covertly via caller-supplied gadget pointers and crafted stack environments.

Confidence: 78%Severity: 85%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:42 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fstack-spoofing-dev%2F@6bef185c40a4487720778910bb191425fece4507e4be1c4f9ada858093f9d3dd
Security Audit — socket — stack-spoofing-dev