aflpp

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This document is a legitimate, detailed AFL++ usage guide intended to maximize fuzzing throughput. It contains no explicit malicious code, obfuscated payloads, or hard-coded secrets. The primary security concerns are operational and supply-chain: (1) use of --privileged Docker with host mounts increases the risk that a compromised fuzzer binary or container image can modify the host; (2) instructions to run root-level scripts and disable kernel mitigations weaken host defenses, enlarging the impact of exploitation; (3) downloading harnesses and headers without integrity checks or pinned image digests creates a supply-chain attack surface. Recommendation: follow the guide only in isolated, ephemeral VMs or air-gapped environments; verify all downloaded artifacts (checksums/signatures), pin Docker images to content digests, avoid --privileged where possible, and never disable kernel mitigations on shared/production hosts.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 07:51 PM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills%2Faflpp%2F@4efc1c1c3b5524b5b8b5531ae6b45b58ff82e9f4