agentsclimarketplace

Analyze suspicious script or document

Skill gaelic-ghost/socket/plugins/cybersecurity-skills/skills/analyze-suspicious-script-or-document

The Source for macOS Agent Workflows

Install
npx -y skills add gaelic-ghost/socket --skill analyze-suspicious-script-or-document

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 6 stars6 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Decode and analyze suspicious scripts and active documents without triggering them. Use for shell, AppleScript, JavaScript, Python, PowerShell, shortcuts, Office files, PDFs, profiles, macros, embedded objects, and staged payloads.

SKILL.md

2.1 KB, as published. Nobody here has run it

Analyze Suspicious Script Or Document

Overview

Recover the execution chain as data. Use parsers and text extraction in isolation, avoid native handlers, and make each decoding transformation reproducible.

Read references/script-document-analysis.md for language and document-specific checks.

Workflow

  1. Preserve the original and identify the real container/type.
  2. Extract without activation.
    • List document members and relationships; extract text, metadata, macros, JavaScript, forms, links, embedded files, and external references with non-executing tooling.
    • Render URLs and commands as inert text.
  3. Normalize one layer at a time.
    • Decode base64/hex/URL escapes, string concatenation, compression, character arithmetic, environment substitution, and generated commands.
    • Record input, operation, tool, and output hash for every layer.
  4. Reconstruct control and data flow.
    • Identify entry conditions, interpreter, downloaded content, execution methods, persistence, credential/file access, network destinations, cleanup, and environment gates.
  5. Separate capability from execution.
    • State which branches are present, which inputs activate them, and which behaviors remain inferred.
  6. Route payloads.
    • Send recovered binaries to static/reverse analysis and use dynamic analysis only inside chosen isolation.

Guardrails

  • Do not paste decoded commands into an executing shell.
  • Do not enable macros, install profiles, follow links, or import shortcuts during static analysis.
  • Do not use a cloud document parser for private content without approval.

Output

Return container identity, recovered layers, execution chain, indicators, activation conditions, likely impact, uncertainty, and safe next step.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.