stack-spoofing-dev
Audited by Socket on Sep 5, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: the scanner hits are mostly false positives, but the skill’s actual purpose is to help an AI agent implement offensive stack-spoofing and EDR-evasion techniques. Its capabilities align with that stated purpose, yet that purpose is itself high risk for an agent skill because it enables stealthy security tradecraft and syscall obfuscation.
High likelihood of malicious/offensive intent: the provided assembly constructs fake stack frames and performs indirect calls to a syscall gadget to spoof execution/call origin. This is a well-known evasion technique used in malware. In a dependency ecosystem, such code represents a serious supply-chain risk because it can execute sensitive syscalls covertly via caller-supplied gadget pointers and crafted stack environments.