godmode

Fail

Audited by Socket on Sep 3, 2026

7 alerts found:

Securityx3Anomalyx3Malware
SecurityMEDIUM
SKILL.md

The skill is internally consistent with its stated purpose, but that purpose is high-risk: it gives an AI agent offensive jailbreak and safety-bypass capabilities, persists those bypasses in local config, and forwards prompts plus API credentials through a third-party routing service. This is best classified as suspicious/high-risk rather than confirmed malware.

Confidence: 93%Severity: 90%
SecurityMEDIUM
scripts/auto_jailbreak.py

This module is highly suspicious and likely malicious in intent: it implements an “auto-jailbreak” pipeline to elicit policy-violating outputs using multiple prompt-injection strategies against LLMs and then persists the best jailbreak configuration to local files. Additionally, it performs unsafe arbitrary code execution via exec() of local script files (parseltongue.py/godmode_race.py) without integrity checks, creating a serious supply-chain/local compromise risk if those files are modified. No obvious cryptomining or OS command execution is present in the provided snippet, but the LLM jailbreak persistence and exec() usage make the overall security risk high.

Confidence: 78%Severity: 80%
SecurityMEDIUM
scripts/load_godmode.py

This module implements a high-risk dynamic code execution loader. It reads and execs Python source files from a directory derived from the HERMES_HOME environment variable, then exports selected functions/constants from those executed scripts into the current module namespace. Even without seeing the loaded scripts’ contents, the design creates a strong supply-chain/local-compromise pathway: if an attacker can influence HERMES_HOME or modify the target directory files, they can execute arbitrary code with the importing process’s privileges. The snippet contains no explicit networking/exfiltration/persistence logic itself, but it provides the necessary execution primitive to do so via the loaded scripts.

Confidence: 82%Severity: 88%
AnomalyLOW
scripts/godmode_race.py

No evidence of traditional host-compromise malware in this module (no execution primitives, persistence, file manipulation, or local data theft). The primary security concern is behavioral and privacy-related: it forwards user-supplied prompts to a third-party LLM gateway (potentially many models concurrently), prints the selected output (risking sensitive data exposure in logs), and includes hardcoded jailbreak-style system prompts plus refusal/hedge heuristics that steer toward non-refusal/unfiltered content. Treat as an LLM proxy with policy-evasion intent and non-trivial data-sharing risk rather than as a stealth malware package.

Confidence: 70%Severity: 55%
AnomalyLOW
scripts/parseltongue.py

This module is a dual-use text obfuscation engine focused on detecting cybersecurity/malware-related keywords and rewriting them with stealthy Unicode/zero-width and encoding transformations (leet, homoglyph-like mappings, ZWJ/ZWNJ insertion, fullwidth, Base64/hex, etc.). There is no direct malware behavior in this fragment (no exec, network, or file/process actions), but the design strongly supports evasion of keyword-based filters or security tooling. Treat as moderate-to-high supply-chain risk depending on how and where it is used.

Confidence: 72%Severity: 62%
AnomalyLOW
references/jailbreak-templates.md

The fragment is an openly documented collection of model-jailbreak prompts and agent-invocation instructions. It does not itself contain clear malware or data theft, but it is designed to bypass model safety controls and includes a risky dynamic exec() example. Treat it as untrusted red-team content; do not install or execute the referenced script without verifying its provenance and contents.

Confidence: 98%Severity: 58%
MalwareHIGH
references/refusal-detection.md

This fragment is a high-risk runtime loader: it reads a Python file from a filesystem location determined by the HERMES_HOME environment variable (defaulting to ~/.hermes) and executes the loaded contents via exec(...), with no integrity verification or safeguards. While the visible demo code only performs refusal detection/score printing, the exec primitive means the executed script could implement arbitrary behavior. Without reviewing godmode_race.py, exact malicious intent cannot be confirmed, but the security risk is substantial and warrants immediate scrutiny and containment.

Confidence: 72%Severity: 88%
Audit Metadata
Analyzed At
Sep 3, 2026, 11:43 AM
Package URL
pkg:socket/skills-sh/atomicbot-ai%2Fatomic-hermes%2Fgodmode%2F@fb4674b51095cd39678d84c2349549b7060ea75b7dfe3e54fcc7f8cdca6e6105
Security Audit — socket — godmode