reverse-engineering
Audited by Socket on May 13, 2026
3 alerts found:
AnomalySecurityx2No direct malware payload is shown; the fragment is an anti-anti-debug/anti-analysis instructional guide. However, it contains highly actionable guidance for defeating common Windows debugger-detection methods (PEB/IsDebuggerPresent/NtQueryInformationProcess/DRx) via in-memory patching and API falsification hooks. As a result, the primary risk is dual-use enablement of evasion, which warrants review of the surrounding package context to determine legitimacy versus malicious incorporation.
SUSPICIOUS. The skill is internally consistent and not deceptive about installs, credentials, or data flows, but it gives an AI agent high-risk reverse-engineering and anti-debug/instrumentation capabilities that fall into the offensive-security-tool category. Supply-chain risk is low from the provided evidence; the main risk is the capability itself.
This content is highly dual-use and centered on runtime tampering: it demonstrates intercepting security-relevant functions and forcing outcomes via return-value replacement and function replacement, along with sensitive logging, memory inspection, and optional instruction tracing. There is no explicit persistence/exfiltration shown in the fragment itself, but its operational purpose strongly aligns with authorization/security bypass and evasion. If such material were included in a software supply chain dependency, it would be a serious review red flag. More context is needed to determine whether a specific package ships this only as documentation/examples or as executable code.