hack
Audited by Socket on Mar 17, 2026
5 alerts found:
Securityx4MalwareThis file is an orchestration layer for offensive security workflows: it fetches exploit feeds, clones repos, generates payloads, and runs external 'skill' scripts and containerized exploit environments. It is dual-use: legitimate for security research or red-team automation, but it presents significant supply-chain and execution risks. The highest risks stem from cloning and executing external repositories and running many external run.sh scripts (which may be under attacker control), AI-generated payload execution, and delegation to other hack.* modules that perform environment setup and exploit execution. I do not see intentional obfuscation or embedded credential theft in this file, but because it executes and writes externally sourced code/payloads it should be treated as high-risk and audited fully (particularly all hack.* modules and any skill run.sh scripts) before use.
This script is intentionally orchestration code for running a hacking/exploit test. It is not obfuscated and does not itself contain payload code or hardcoded credentials, but it explicitly invokes an 'exploit' step targeting a hardcoded IP and executes external scripts and a payload file. That makes it potentially dangerous: running this script will execute arbitrary code (the run.sh helpers and the payload) and likely generate network attacks against the specified target. If you do not control the target or the helper scripts, do not run this. The fragment should be treated as high-risk behavior (offensive action) even though the maliciousness of the package depends on the contents of the invoked helper scripts and payload.
This module is high risk. It purposefully facilitates exploit ideation and assembly payload generation and calls an external script from a configurable path without integrity checks, sandboxing, or input validation. Multiple coding errors (undefined 'goal', incorrect return types, broken __all__) show the file is incomplete and likely unsafe to run. Recommend not executing this module in production or sensitive environments. If maintained, require: remove/disable offensive-generation capabilities or add strict access controls and auditing, validate/sanitize inputs, add integrity verification for CODEX_SKILL/run.sh, handle timeouts and errors safely, and fix the logic bugs and exports.
This document is an explicit exploit description that instructs how to achieve arbitrary code execution inside SEV-SNP protected VMs by exploiting a VMRUN microcode race to corrupt the guest stack pointer and inject a ROP chain. It is malicious in intent (offensive guidance) and represents a high security risk to systems using affected AMD CPUs and SEV-SNP. Remediation requires microcode/firmware and hypervisor fixes; treat this as an actionable exploit disclosure.
SUSPICIOUS. The skill’s footprint is dominated by offensive security capabilities that let an AI agent scan targets, retrieve exploit material, and execute PoCs, with explicit stealth modes and iterative exploitation. Containerization may reduce some host impact, but it does not make the behavior proportionate or safe, and the unspecified ./run.sh/container provenance plus transitive skill delegation materially increase risk.