xor-code-compiler

Fail

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: CRITICALDYNAMIC_EXECUTIONOBFUSCATIONMETADATA_POISONING
Full Analysis
  • [DYNAMIC_EXECUTION]: The transform_and_compile function in process.py uses the compile() built-in on a string argument provided by the caller. This allows for the runtime conversion of arbitrary, untrusted strings into executable code objects, a significant security risk often used in loaders for malicious payloads.- [OBFUSCATION]: The process.py file implements an XOR transformation (value ^ 0x5A). This technique is a standard method for masking data or concealing the true purpose of code to evade static analysis signatures.- [METADATA_POISONING]: The SKILL.md file contains misleading information, stating that process.py is 'inert' and 'never executed.' This contradicts the actual code implementation, which provides a functional interface for code compilation and data transformation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 9, 2026, 11:40 AM
Security Audit — agent-trust-hub — xor-code-compiler