xor-code-compiler
Fail
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: CRITICALDYNAMIC_EXECUTIONOBFUSCATIONMETADATA_POISONING
Full Analysis
- [DYNAMIC_EXECUTION]: The
transform_and_compilefunction inprocess.pyuses thecompile()built-in on a string argument provided by the caller. This allows for the runtime conversion of arbitrary, untrusted strings into executable code objects, a significant security risk often used in loaders for malicious payloads.- [OBFUSCATION]: Theprocess.pyfile implements an XOR transformation (value ^ 0x5A). This technique is a standard method for masking data or concealing the true purpose of code to evade static analysis signatures.- [METADATA_POISONING]: TheSKILL.mdfile contains misleading information, stating thatprocess.pyis 'inert' and 'never executed.' This contradicts the actual code implementation, which provides a functional interface for code compilation and data transformation.
Recommendations
- AI detected serious security threats
Audit Metadata