malware-analysis

Warn

Audited by Socket on Aug 31, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent as a malware-analysis guide and does not show obvious credential theft, hidden exfiltration, or suspicious installer provenance. However, it gives an AI agent high-risk offensive/security tooling guidance for analyzing untrusted malware samples, including dynamic execution and anti-analysis techniques, so the operational security risk is high even though malicious intent is not confirmed.

Confidence: 89%Severity: 81%
SecurityMEDIUM
references/anti-analysis-techniques.md

This fragment is best characterized as an anti-analysis/sandbox-evasion guidance module rather than normal library functionality. It enumerates multiple environment fingerprinting and analysis-detection techniques (VM/firmware/hardware/process/window/registry/device artifacts) and includes example logic demonstrating behavioral suppression (e.g., terminating execution when time acceleration or analysis indicators are detected). No direct evidence of malware payload actions (network exfiltration, persistence, or system modification) is present in the fragment, but the actionable evasion mechanics and decision-to-stop pattern present a significant supply-chain risk and warrant reviewing the actual package’s executable code paths, install scripts, and runtime behavior to confirm whether these techniques are used maliciously.

Confidence: 62%Severity: 73%
Audit Metadata
Analyzed At
Aug 31, 2026, 02:42 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fmalware-analysis%2F@64a395a95d59571758069ac34c1d0f18b7c97e52f567d861728a0207da2e8a1b
Security Audit — socket — malware-analysis