stack-overflow-and-rop
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The skill is internally consistent as an exploit-development guide, but its stated purpose is to enable offensive binary exploitation, bypass mitigations, and extract data/execute code on targets. The scanner's command-injection hits are benign markdown artifacts, yet the overall skill remains high risk because it equips an AI agent with penetration-testing and exploitation procedures.
This fragment is exploit-development guidance that directly enables control-flow hijacking (ROP/COP/JOP, ret2csu) and syscall-based open/read/write actions to exfiltrate a sensitive file (e.g., ‘flag’). While it does not, by itself, demonstrate executable malware logic, its contents are strongly offensive and would be highly concerning if embedded within a software dependency intended for benign use. Further review of surrounding package files would be needed to confirm whether it is merely documentation or part of runtime/packaging logic.