agentsclimarketplace

Perform dynamic malware analysis

Skill gaelic-ghost/socket/skills/perform-dynamic-malware-analysis

Observe suspicious content in a disposable, instrumented environment. Use when execution, process ancestry, file changes, persistence, network behavior, configuration decryption, child payloads, environment gates, or user interaction must be measured after static analysis and an isolation boundary, authorization, baseline, stop conditions, evidence export, and teardown plan are explicit.From its SKILL.md

Install
npx -y skills add gaelic-ghost/socket --skill perform-dynamic-malware-analysis

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 6 stars6 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

2.4 KB, 400 tokens by cl100k_base, as published. Nobody here has run it

Perform Dynamic Malware Analysis

Overview

Execute only inside an environment chosen by select-analysis-isolation and preflighted by prepare-isolated-analysis-lab, with an observation plan that can distinguish artifact behavior from baseline noise. Preserve the exact sample, prepared-lab record, and environment identity.

Read references/dynamic-observation-plan.md for baseline, stimulus, telemetry, and teardown fields.

Workflow

  1. Define the unresolved question and minimum stimulus.
  2. Verify isolation.
    • Require the prepared-lab record and verify its guest/platform build, baseline/reset state, accounts, shares, clipboard, devices, credentials, network mode, monitoring, stop controls, export path, and teardown plan are still current.
    • Record virtualization artifacts or anti-VM behavior that may affect the conclusion.
  3. Capture a baseline.
    • Record processes, files/registrations, persistence surfaces, network state, services, and relevant logs before execution.
  4. Execute one controlled step.
    • Record command/UI action, time, user/privilege, environment variables, arguments, and interactions.
    • Do not improvise additional payloads, credentials, or targets.
  5. Observe behavior.
    • Correlate process tree, file/registry or platform state, persistence, permissions, child artifacts, network/DNS, logs, prompts, crashes, and timing.
    • Hash and preserve dropped/modified artifacts as new evidence.
  6. Repeat only to answer a named question.
    • Change one variable at a time and revert to the baseline snapshot.
  7. Export and tear down.
    • Export only intended evidence, scan it before host use, destroy/revert the environment, and revoke temporary access.

Output

Return the prepared-lab identity, environment/baseline identity, stimulus, observed timeline, artifacts and indicators, absent expected behavior, virtualization/evasion/coverage limits, conclusion, and teardown verification.

What ships with it: 2 files

914 B alongside SKILL.md

agents/

Keep looking

Skills are one crate of 326,835. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.