Agent skill

Mal Develop

by chainreactors in chainreactors/malice-network

MAL (Malice Scripting Language) plugin development guide. An agent skill from chainreactors/malice-network.

Apache-2.0Auto-check passedAgent Workflows

Install Mal Develop

skills CLI
$ npx skills add chainreactors/malice-network --skill mal-develop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install chainreactors/malice-network mal-develop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/chainreactors/malice-network.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mal-develop .claude/skills/mal-develop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mal-develop
GitHub stars
500
Token cost
~1.4k tokens
SKILL.md length
219 words
Files
5
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

MAL (Malice Scripting Language) plugin development guide. An agent skill from chainreactors/malice-network.

  • Works in 6 steps: Create → Write → Load and Test → …
  • Conditions: when users want to write MAL plugins
  • SKILL.md covers Plugin Structure at a Glance, Quick Example: Registering a…, High-Frequency API Quick… and Development Workflow, plus 1 more section
  • Reaches github.com

What it does

Mal Develop is an agent skill from chainreactors/malice-network. MAL (Malice Scripting Language) plugin development guide. Helps users write Lua plugins for IoM, covering plugin structure, command registration, BOF invocation, resource management, event callbacks, testing, debugging, and publishing workflows. Trigger conditions: when users want to write MAL plugins, extend IoM commands, write Lua scripts, integrate BOFs, develop custom modules, or ask questions like "how to write a mal plugin", "how to add a new command to IoM", or "what Lua APIs are available".

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `reference/api-reference.md`, `reference/examples.md` and `reference/plugin-structure.md`).

It sits in Agent Workflows, covering Hooks and plugins. It works with Lua. The repository describes itself as: Next Generation C2 Framework, IoM-server/client. The licence is Apache-2.0.

When your agent uses it

  • Conditions: when users want to write MAL plugins
  • Extend IoM commands
  • Write Lua scripts
  • Develop custom modules

Example prompts

  • “how to write a mal plugin”
  • “how to add a new command to IoM”
  • “what Lua APIs are available”
  • “/mal-develop”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Create
  2. Write
  3. Load and Test
  4. Verify
  5. Debug (on failure)
  6. Publish

What it can do on your machine

Read from SKILL.md and the folder at commit 6c0e358. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are lua, bash and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • chainreactors.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mal Develop loads about 1.4k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 219 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from chainreactors/malice-network at commit 6c0e358, republished under its Apache-2.0 licence (© chainreactors). 219 words, ~1,414 tokens.

Download SKILL.mdSave it as .claude/skills/mal-develop/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
mal-develop
description
MAL (Malice Scripting Language) plugin development guide. Helps users write Lua plugins for IoM, covering plugin structure, command registration, BOF invocation, resource management, event callbacks, testing, debugging, and publishing workflows. Trigger conditions: when users want to write MAL plugins, extend IoM commands, write Lua scripts, integrate BOFs, develop custom modules, or ask questions like "how to write a mal plugin", "how to add a new command to IoM", or "what Lua APIs are available".

MAL Plugin Development Guide

MAL is the Lua 5.1 plugin system for IoM. It extends the client with Lua scripts. Each plugin can register new commands, invoke BOFs, execute implant modules, and listen for events.

Plugin Structure at a Glance

my-plugin/
├── mal.yaml             # Plugin manifest (required)
├── main.lua             # Entry script (required)
├── modules/             # Lua modules (optional, used via require)
│   └── utils.lua
└── resources/           # Resource files (optional, BOFs, DLLs, etc.)
    └── bof/
        ├── tool.x64.o
        └── tool.x86.o
mal.yaml
yaml
name: my-plugin
type: lua
author: your-name
version: 1.0.0
entry: main.lua          # Entry file
lib: false               # true = library-only plugin (does not register commands)
depend_modules: []       # Required implant modules
depend_armory: []        # Required armory resources

See reference/plugin-structure.md for details.

Quick Example: Registering a Command

lua
-- main.lua
local function run_hello(arg_name, cmd)
    print("Hello, " .. (arg_name or "world"))
end

local cmd = command("hello", run_hello, "Say hello", "")
opsec("hello", 10.0)
help("hello", "Usage: hello [name]")

High-Frequency API Quick Reference

Sorted by usage frequency, these are the most commonly used functions when developing MAL plugins:

FunctionPurposeFrequency
command(name, fn, short, ttp)Register a commandHighest
active()Get the current sessionVery high
script_resource(path)Get a plugin resource pathVery high
opsec(name, score)Set OPSEC scoreHigh
bof(session, path, args, output)Execute a BOFHigh
bof_pack(format, ...)Pack BOF argumentsHigh
bexecute_assembly(session, path, args)Execute .NET assemblyMedium
help(name, text)Set help textMedium
new_sacrifice(ppid, block, etw, amsi, argue)Sacrifice process configMedium
Parameter Conventions
lua
local function handler(arg_target, flag_port, cmdline, args, cmd)
    -- arg_target  -> positional argument    flag_port -> --port flag
    -- cmdline     -> command line           args      -> argument array
    -- cmd         -> cobra.Command object
end
BOF Argument Format
lua
bof_pack("Ziz", wide_string, integer, ansi_string)
-- z=ANSI string  Z=wide string  i=int32  s=int16  b=binary

See reference/api-reference.md for the full API reference.

Development Workflow

 Create          Write          Load          Verify         Debug          Publish
┌─────┐      ┌─────┐      ┌─────┐      ┌─────┐      ┌─────┐      ┌─────┐
│mkdir│─────→│ lua │─────→│load │─────→│test │─────→│ fix │─────→│push │
│yaml │      │code │      │     │      │     │      │     │      │     │
└─────┘      └─────┘      └─────┘      └─────┘      └──┬──┘      └─────┘
                                                        │
                                                  ┌─────┘
                                                  ↓ loop
                                               ┌─────┐
                                               │write │
                                               └─────┘
1. Create
bash
mkdir -p my-plugin/resources/bof
# Write mal.yaml
2. Write
bash
# Write main.lua, starting with the simplest command
# Refer to patterns in reference/examples.md
3. Load and Test
mal load /path/to/my-plugin
4. Verify
search_commands("my-command")       # Confirm command registration succeeded
my-command --help                   # Confirm help text is correct
my-command <test-args>              # Execute for real (requires a session)
5. Debug (on failure)
# Check logs
# print() in Lua outputs directly to the terminal
# After modifications, reload:
mal remove my-plugin
mal load /path/to/my-plugin
6. Publish
mal install /path/to/my-plugin.tar.gz    # Local install
# Or submit to https://github.com/chainreactors/mal-community

See reference/testing.md for detailed testing and verification methods.

Reference Documentation

TopicReference File
Full API Referencereference/api-reference.md
Plugin Structure Detailsreference/plugin-structure.md
Practical Examplesreference/examples.md
Testing, Verification & Debuggingreference/testing.md
External Documentation
ResourceLink
MAL Quick Starthttps://chainreactors.github.io/wiki/IoM/manual/mal/quickstart/
IoM Wikihttps://chainreactors.github.io/wiki/IoM/
Community Plugin Repositoryhttps://github.com/chainreactors/mal-community
Implant Repositoryhttps://github.com/chainreactors/malefic
Community Plugin Sourcehelper/intl/community/modules/ (best learning reference)

© chainreactors, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in skills/mal-develop of chainreactors/malice-network.

  • SKILL.md
  • reference/api-reference.md
  • reference/examples.md
  • reference/plugin-structure.md
  • reference/testing.md

Open the folder on GitHubat commit 6c0e358

Compare with similar skills

Mal Develop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mal Develop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mal Develop this skillchainreactors/malice-network500—~1.4kAutomated safety check: PassApache-2.0
Nvim PluginS1M0N38/love2d.nvim216—~1kAutomated safety check: PassMIT
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official37k11 repos~4.1kAutomated safety check: NotesApache-2.0
Claude Code Agent Developmentanthropics/claude-plugins-official37k8 repos~2.8kAutomated safety check: PassApache-2.0
Claude Code Skill Developer Guidediet103/claude-code-infrastructure-showcase10k10 repos~3.5kAutomated safety check: PassMIT
Plugin Settings Patternanthropics/claude-plugins-official37k7 repos~3kAutomated safety check: PassApache-2.0

Similar skills

  • Nvim Plugin

    S1M0N38/love2d.nvim

    Neovim plugin development best practices and patterns for love2d.nvim.

    216 GitHub stars~1k tokensUpdated 3 mo ago
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    37k GitHub starsUsed in 11 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    37k GitHub starsUsed in 8 repos~2.8k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Skill Developer Guide

    diet103/claude-code-infrastructure-showcase

    A guide to creating and managing Claude Code skills with auto-activation: skill-rules.json triggers, hooks, enforcement levels, YAML frontmatter and progressive disclosure.

    10k GitHub starsUsed in 10 repos~3.5k tokens
    Agent WorkflowsAuto-check passed
  • Plugin Settings Pattern

    anthropics/claude-plugins-official

    Official

    Shows how Claude Code plugins keep per-project settings and state in .claude/plugin-name.local.md files with YAML frontmatter and a markdown body.

    37k GitHub starsUsed in 7 repos~3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    37k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed

More from chainreactors/malice-network

  • Iom Opsec

    chainreactors/malice-network

    IoM Operational Security (OPSEC) advisor. An agent skill from chainreactors/malice-network.

    500 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Mal Develop

What does Mal Develop do?

MAL (Malice Scripting Language) plugin development guide. An agent skill from chainreactors/malice-network. Mal Develop is an agent skill from chainreactors/malice-network. MAL (Malice Scripting Language) plugin development guide.

When should I use Mal Develop?

Mal Develop fits situations like: conditions: when users want to write MAL plugins; extend IoM commands; write Lua scripts; develop custom modules.

How do I install Mal Develop in Claude Code?

Run `npx skills add chainreactors/malice-network --skill mal-develop -a claude-code`. Or copy the skill folder (skills/mal-develop in chainreactors/malice-network) into .claude/skills/mal-develop in your project. Claude Code loads it when a task matches its description.

How do I install Mal Develop in Codex?

Run `npx skills add chainreactors/malice-network --skill mal-develop -a codex`. Or copy the skill folder (skills/mal-develop in chainreactors/malice-network) into .agents/skills/mal-develop in your project. Codex loads it when a task matches its description.

Can I use Mal Develop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add chainreactors/malice-network --skill mal-develop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mal-develop, .gemini/skills/mal-develop, .github/skills/mal-develop and .opencode/skills/mal-develop in your project.

What does Mal Develop need to run?

SKILL.md names no scripts, command-line tools or credentials: Mal Develop is instructions for the agent only.

Does Mal Develop access the network?

SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: chainreactors.github.io. This is read from the text; nothing was executed.

Is Mal Develop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mal Develop use?

Mal Develop is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mal Develop use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mal Develop?

Skills that share tags, products or a category with Mal Develop: Nvim Plugin (S1M0N38/love2d.nvim, 216 stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 37k stars), Claude Code Agent Development (anthropics/claude-plugins-official, 37k stars) and Claude Code Skill Developer Guide (diet103/claude-code-infrastructure-showcase, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mal Develop?

chainreactors (a GitHub organization) maintains it in chainreactors/malice-network, which has 500 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 5, 2026.

Source: chainreactors/malice-network on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.