ghost-bits-cast-attack

Fail

Audited by Socket on Jul 21, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: internally consistent as an offensive exploit playbook, but high risk because it equips an AI agent to conduct defense evasion, exploitation, and chaining against live Java services. Little supply-chain risk, but the capability itself is a high-risk offensive security skill.

Confidence: 95%Severity: 90%
MalwareHIGH
PAYLOAD_COOKBOOK.md

This fragment is highly consistent with malicious exploitation tooling. It provides parameterized Unicode/byte desynchronization (“Ghost Bits”) to bypass WAF/IDS normalization and deliver dangerous payloads via HTTP requests, including patterns consistent with traversal/CRLF-style injection and multipart filename-based upload/webshell attempts. There is no benign protective functionality in the core payload generators; the detection pseudocode primarily mirrors attacker parsing to enable evasion. Treat inclusion in a software supply chain as an extreme security risk and investigate for malicious intent and persistence mechanisms beyond this excerpt.

Confidence: 88%Severity: 93%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fghost-bits-cast-attack%2F@56ec2d900df5fb20c0d4d63a4e914f5be616e7231aeec7f5925d1712ee153d19
Security Audit — socket — ghost-bits-cast-attack