Avast Security Awareness

reason-machines/security-skills/skills/avast-security-awareness

作者 reason-machines304c245fe992无许可证11 个星标收录于 2026年10月9日更新于 2026年10月9日仓库2个月前更新

Recognize and avoid malicious software distribution repositories disguised as legitimate security tools

仅含说明Security
AI 生成的概览

教导智能体识别并警告伪装成安全软件的恶意软件分发仓库。

功能
这是一个仅含说明的技能,指导智能体识别那些冒充正规安全软件、实则遵循恶意软件分发模式的仓库。它列出诸如 keygen、crack 等关键词、夸大的版本声明、缺少源代码或文档、主题不匹配等危险信号,并提供用于关键词检查、用户警告和安全来源查询的 Go 示例代码。它产出的是警告信息和安全替代建议,而不是文件或扫描结果。
适用场景
当用户询问某个安全软件仓库是否正规、如何识别恶意软件分发或破解软件骗局、或如何核实官方软件来源时使用。它适用于有关可疑 keygen、激活工具和非官方下载的问题。
运行要求
无需脚本或工具,仅为说明性内容。其中的 Go 示例仅作演示,不会被执行,也不需要凭据或网络访问。

Avast Security Awareness Skill

Skill by ara.so — Security Skills collection.

⚠️ Critical Security Warning

This repository is NOT a legitimate Avast product and represents a common malware distribution pattern. This skill teaches AI agents to identify and warn users about such threats.

What This Skill Does

This skill enables AI coding agents to:

  • Recognize malicious software distribution repositories
  • Identify red flags in repository descriptions and content
  • Educate users on safe software acquisition practices
  • Prevent installation of potentially malicious software
  • Guide users to legitimate security software sources

Identifying Malicious Repository Patterns

Red Flags Present in This Repository

  1. Suspicious Keywords: "Keygen", "Crack", "Pre-Activated", "Loader", "Serial"
  2. Version Manipulation: Claims of future versions (2026 when current year is earlier)
  3. No Source Code: No actual implementation despite claiming to be a Go project
  4. Artificial Engagement: Star velocity inconsistent with legitimate projects
  5. Missing Documentation: No README or legitimate setup instructions
  6. License Issues: NOASSERTION license for "open source" security software
  7. Mismatched Topics: Topics like "retdec" unrelated to described functionality

Detection Code Example (Go)

go
package malwaredetect
import (    "strings"    "regexp")
type RepositoryAnalyzer struct {    SuspiciousKeywords []string    MinimumREADMELength int}
func NewAnalyzer() *RepositoryAnalyzer {    return &RepositoryAnalyzer{        SuspiciousKeywords: []string{            "keygen", "crack", "pre-activated", "loader",            "serial", "full version", "setup keygen",        },        MinimumREADMELength: 100,    }}
func (a *RepositoryAnalyzer) AnalyzeRepository(description, readme string) (bool, []string) {    var warnings []string    isSuspicious := false
    // Check for suspicious keywords    descLower := strings.ToLower(description)    for _, keyword := range a.SuspiciousKeywords {        if strings.Contains(descLower, keyword) {            warnings = append(warnings, "Contains suspicious keyword: "+keyword)            isSuspicious = true        }    }
    // Check for missing or minimal README    if len(readme) < a.MinimumREADMELength {        warnings = append(warnings, "Missing or insufficient documentation")        isSuspicious = true    }
    // Check for premium software offered for free    premiumPattern := regexp.MustCompile(`(?i)(premium|pro|full version).*free`)    if premiumPattern.MatchString(descLower) {        warnings = append(warnings, "Claims to offer premium software for free")        isSuspicious = true    }
    return isSuspicious, warnings}
func (a *RepositoryAnalyzer) GetSecurityRecommendation(repoName string) string {    return "Do not download or execute files from " + repoName + ". " +           "Obtain security software only from official vendor websites."}

Safe Security Software Practices

Legitimate Sources

Always obtain security software from:

go
package securitysources
var LegitimateSecurityVendors = map[string]string{    "Avast": "https://www.avast.com/",    "Norton": "https://www.norton.com/",    "Bitdefender": "https://www.bitdefender.com/",    "Kaspersky": "https://www.kaspersky.com/",    "ESET": "https://www.eset.com/",}
func GetOfficialDownloadURL(vendor string) (string, bool) {    url, exists := LegitimateSecurityVendors[vendor]    return url, exists}

User Warning System

go
package userwarning
import (    "fmt"    "os")
type SecurityAlert struct {    Severity string    Message  string    Action   string}
func CreateCriticalAlert(repoName string) SecurityAlert {    return SecurityAlert{        Severity: "CRITICAL",        Message: fmt.Sprintf(            "Repository '%s' exhibits patterns consistent with malware distribution",            repoName,        ),        Action: "Do not clone, download, or execute any files. Report repository to platform.",    }}
func DisplayAlert(alert SecurityAlert) {    fmt.Fprintf(os.Stderr, "\n🚨 [%s] SECURITY ALERT\n", alert.Severity)    fmt.Fprintf(os.Stderr, "⚠️  %s\n", alert.Message)    fmt.Fprintf(os.Stderr, "✋ ACTION REQUIRED: %s\n\n", alert.Action)}

Agent Response Pattern

When a user asks about this or similar repositories:

go
package agentresponse
import "fmt"
func RespondToSuspiciousRepo(repoURL string) string {    return fmt.Sprintf(`⛔ SECURITY WARNING ⛔
The repository at %s appears to be a malware distribution site.
RED FLAGS:- Offers "cracked" or "pre-activated" commercial software- Contains suspicious keywords (keygen, loader, serial)- No legitimate source code or documentation- Illegal distribution of copyrighted software
RISKS:- Malware installation (trojans, ransomware, spyware)- Credential theft- System compromise- Legal consequences for software piracy
SAFE ALTERNATIVE:Visit the official Avast website: https://www.avast.com/Use free legitimate versions or purchase licenses directly.
DO NOT:❌ Clone this repository❌ Download any files❌ Run any executables❌ Enter credentials
DO:✅ Report this repository to GitHub✅ Use official software sources only✅ Keep your antivirus updated from legitimate sources`, repoURL)}

Reporting Malicious Repositories

bash
# Report to GitHub (use web interface)# Navigate to repository → Settings → Report content
# Verify legitimate software signatures# Windows example:signtool verify /pa /v "downloaded_file.exe"
# Check file hash against official vendor checksums# Linux/macOS:sha256sum downloaded_file.exe# Compare with official vendor website hash

Environment Variables for Security Checks

bash
# Configure security scanning thresholdsexport MALWARE_SCAN_ENABLED=trueexport REPO_VERIFICATION_LEVEL=strictexport WARN_ON_MISSING_README=trueexport BLOCK_KEYGEN_KEYWORDS=true

Conclusion

This skill equips AI agents to protect users from malware distribution disguised as legitimate software repositories. Always prioritize user safety by identifying threats and providing secure alternatives.

Remember: Legitimate security software vendors never distribute through unofficial GitHub repositories with activation cracks or keygens.

来源与署名

来源:reason-machines/security-skills位于skills/avast-security-awareness提交304c245

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架