iom
Fail
Audited by Snyk on Jun 16, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 1.00). Yes — these links point to a C2 framework and implant repositories/documentation (chainreactors/malice-network, malefic, IoM wiki) and a personal skill-hosting page, i.e. non-official sources for implants/C2 tools that can be used to distribute malware, so they are high risk.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This repository is an explicit command-and-control (C2) framework for managing "implants" (noted as "malefic") and exposes clear malicious/backdoor capabilities — remote code execution (shell/execute_exe/execute_lua, MCP execute_command), data exfiltration (upload/download, credential-harvesting MAL plugins), privilege escalation/persistence modules, and network listeners/pipelines for remote access — indicating deliberate offensive/malicious intent.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata