SkillTotal
cd ~/labs
visitor@skilltotal:~$ cat ./labs/obfuscated-code/mission.txt

Obfuscated Code

lab 13 · ST-OBF-DECODE-EXEC · LLM05
mission.txt
scenario

An agent runs a snippet after a safety scan. The scan flags a dangerous call — eval, exec — whose argument is a readable command (curl … | sh). It does not understand the string, only reads it.

objective

Get a payload to run that the scanner cannot read — the dangerous command must not appear as plain text in the call.

session — obfuscated-code
snippet.js
Or start from:
▚ Intel

No leads yet. Declassify intel one step at a time when you’re stuck.

▰ Dossierclassified — solve to unseal

How this attack works

The scanner matched the text of the argument passed to the exec sink. Encoding the command as base64 made that text meaningless; the snippet decoded it at runtime and executed the result, so the dangerous string never appeared for the scanner to see.

Why it's dangerous

Decode-then-execute is one of the most common shapes of real npm and PyPI malware: the package looks inert, then reconstructs and runs its payload at install or import time. Any defense that only reads string literals is blind to it. SkillTotal flags a decode call feeding an exec sink as ST-OBF-DECODE-EXEC, regardless of the encoding.

OWASP mapping

Maps to OWASP Top 10 for LLM Applications (2025): LLM05: Improper Output Handling (executing model- or dependency-supplied code). SkillTotal’s ST-OBF-DECODE-EXEC flags decode-then-run across languages.

How to defend

  • Flag the structure, not the string: a decode (atob/Buffer.from/fromCharCode) feeding eval/Function/exec is the signal.
  • Forbid dynamic code execution entirely where you can; there is rarely a legitimate `eval(decode(...))`.
  • Run untrusted code in a sandbox with no network egress and no credentials.
  • Scan at the AST level, after constant-folding obvious decodes, not with text regexes alone.

SkillTotal catches this class of issue deterministically (rule ST-OBF-DECODE-EXEC).

Scan AI component (free)

FAQ

Isn't eval always obvious?
The call is; the payload is not. Scanners and reviewers often allow eval/Function and only inspect the argument. Encoding the argument defeats that, which is why the decode→exec pair, not eval alone, is the thing to flag.
Why does real malware do this?
To pass registry scanning and casual review. The published source looks benign; the malicious command only exists after a runtime decode, at install or import time.