windows-internals-dev
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of reference documentation (.md files) describing Windows kernel structures (PEB, TEB, EPROCESS), binary formats (PE/COFF), and system mechanisms (syscalls, exception handling). No executable scripts (.sh, .py, .js) or binary artifacts are included.
- [SAFE]: While the documentation covers topics often used in exploit development (AMSI patching, syscall resolution, stack spoofing), it is presented as a structural reference for developers and lab work. The techniques described are standard architectural knowledge in Windows systems programming and security research.
- [METADATA_POISONING]: No deceptive metadata or hidden instructions were found. The skill accurately identifies itself as an 'Auth/lab dev' reference for Windows internals.
Audit Metadata