Nvim Plugin
S1M0N38/love2d.nvim
Neovim plugin development best practices and patterns for love2d.nvim.
MAL (Malice Scripting Language) plugin development guide. An agent skill from chainreactors/malice-network.
$ npx skills add chainreactors/malice-network --skill mal-develop -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install chainreactors/malice-network mal-develop --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/chainreactors/malice-network.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mal-develop .claude/skills/mal-develop && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mal-develop" agent skill from https://github.com/chainreactors/malice-network/tree/dev/skills/mal-develop into .claude/skills/mal-develop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mal-develop", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/chainreactors/malice-network/tree/dev/skills/mal-developType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add chainreactors/malice-network --skill mal-develop -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install chainreactors/malice-network mal-develop --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chainreactors/malice-network.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/mal-develop .agents/skills/mal-develop && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mal-develop" agent skill from https://github.com/chainreactors/malice-network/tree/dev/skills/mal-develop into .agents/skills/mal-develop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mal-develop", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add chainreactors/malice-network --skill mal-develop -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install chainreactors/malice-network mal-develop --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chainreactors/malice-network.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/mal-develop .cursor/skills/mal-develop && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mal-develop" agent skill from https://github.com/chainreactors/malice-network/tree/dev/skills/mal-develop into .cursor/skills/mal-develop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mal-develop", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/chainreactors/malice-network.git --path skills/mal-develop--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add chainreactors/malice-network --skill mal-develop -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install chainreactors/malice-network mal-develop --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chainreactors/malice-network.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/mal-develop .gemini/skills/mal-develop && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mal-develop" agent skill from https://github.com/chainreactors/malice-network/tree/dev/skills/mal-develop into .gemini/skills/mal-develop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mal-develop", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install chainreactors/malice-network mal-developInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add chainreactors/malice-network --skill mal-develop -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/chainreactors/malice-network.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/mal-develop .github/skills/mal-develop && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mal-develop" agent skill from https://github.com/chainreactors/malice-network/tree/dev/skills/mal-develop into .github/skills/mal-develop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mal-develop", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add chainreactors/malice-network --skill mal-develop -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install chainreactors/malice-network mal-develop --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chainreactors/malice-network.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/mal-develop .opencode/skills/mal-develop && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mal-develop" agent skill from https://github.com/chainreactors/malice-network/tree/dev/skills/mal-develop into .opencode/skills/mal-develop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mal-develop", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mal-developMAL (Malice Scripting Language) plugin development guide. An agent skill from chainreactors/malice-network.
Mal Develop is an agent skill from chainreactors/malice-network. MAL (Malice Scripting Language) plugin development guide. Helps users write Lua plugins for IoM, covering plugin structure, command registration, BOF invocation, resource management, event callbacks, testing, debugging, and publishing workflows. Trigger conditions: when users want to write MAL plugins, extend IoM commands, write Lua scripts, integrate BOFs, develop custom modules, or ask questions like "how to write a mal plugin", "how to add a new command to IoM", or "what Lua APIs are available".
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `reference/api-reference.md`, `reference/examples.md` and `reference/plugin-structure.md`).
It sits in Agent Workflows, covering Hooks and plugins. It works with Lua. The repository describes itself as: Next Generation C2 Framework, IoM-server/client. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6c0e358. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are lua, bash and yaml).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
chainreactors.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mal Develop loads about 1.4k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 219 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from chainreactors/malice-network at commit 6c0e358, republished under its Apache-2.0 licence (© chainreactors). 219 words, ~1,414 tokens.
.claude/skills/mal-develop/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.MAL is the Lua 5.1 plugin system for IoM. It extends the client with Lua scripts. Each plugin can register new commands, invoke BOFs, execute implant modules, and listen for events.
my-plugin/
├── mal.yaml # Plugin manifest (required)
├── main.lua # Entry script (required)
├── modules/ # Lua modules (optional, used via require)
│ └── utils.lua
└── resources/ # Resource files (optional, BOFs, DLLs, etc.)
└── bof/
├── tool.x64.o
└── tool.x86.oname: my-plugin
type: lua
author: your-name
version: 1.0.0
entry: main.lua # Entry file
lib: false # true = library-only plugin (does not register commands)
depend_modules: [] # Required implant modules
depend_armory: [] # Required armory resourcesSee reference/plugin-structure.md for details.
-- main.lua
local function run_hello(arg_name, cmd)
print("Hello, " .. (arg_name or "world"))
end
local cmd = command("hello", run_hello, "Say hello", "")
opsec("hello", 10.0)
help("hello", "Usage: hello [name]")Sorted by usage frequency, these are the most commonly used functions when developing MAL plugins:
| Function | Purpose | Frequency |
|---|---|---|
command(name, fn, short, ttp) | Register a command | Highest |
active() | Get the current session | Very high |
script_resource(path) | Get a plugin resource path | Very high |
opsec(name, score) | Set OPSEC score | High |
bof(session, path, args, output) | Execute a BOF | High |
bof_pack(format, ...) | Pack BOF arguments | High |
bexecute_assembly(session, path, args) | Execute .NET assembly | Medium |
help(name, text) | Set help text | Medium |
new_sacrifice(ppid, block, etw, amsi, argue) | Sacrifice process config | Medium |
local function handler(arg_target, flag_port, cmdline, args, cmd)
-- arg_target -> positional argument flag_port -> --port flag
-- cmdline -> command line args -> argument array
-- cmd -> cobra.Command object
endbof_pack("Ziz", wide_string, integer, ansi_string)
-- z=ANSI string Z=wide string i=int32 s=int16 b=binarySee reference/api-reference.md for the full API reference.
Create Write Load Verify Debug Publish
┌─────┐ ┌─────┐ ┌─────┐ ┌─────┐ ┌─────┐ ┌─────┐
│mkdir│─────→│ lua │─────→│load │─────→│test │─────→│ fix │─────→│push │
│yaml │ │code │ │ │ │ │ │ │ │ │
└─────┘ └─────┘ └─────┘ └─────┘ └──┬──┘ └─────┘
│
┌─────┘
↓ loop
┌─────┐
│write │
└─────┘mkdir -p my-plugin/resources/bof
# Write mal.yaml# Write main.lua, starting with the simplest command
# Refer to patterns in reference/examples.mdmal load /path/to/my-pluginsearch_commands("my-command") # Confirm command registration succeeded
my-command --help # Confirm help text is correct
my-command <test-args> # Execute for real (requires a session)# Check logs
# print() in Lua outputs directly to the terminal
# After modifications, reload:
mal remove my-plugin
mal load /path/to/my-pluginmal install /path/to/my-plugin.tar.gz # Local install
# Or submit to https://github.com/chainreactors/mal-communitySee reference/testing.md for detailed testing and verification methods.
| Topic | Reference File |
|---|---|
| Full API Reference | reference/api-reference.md |
| Plugin Structure Details | reference/plugin-structure.md |
| Practical Examples | reference/examples.md |
| Testing, Verification & Debugging | reference/testing.md |
| Resource | Link |
|---|---|
| MAL Quick Start | https://chainreactors.github.io/wiki/IoM/manual/mal/quickstart/ |
| IoM Wiki | https://chainreactors.github.io/wiki/IoM/ |
| Community Plugin Repository | https://github.com/chainreactors/mal-community |
| Implant Repository | https://github.com/chainreactors/malefic |
| Community Plugin Source | helper/intl/community/modules/ (best learning reference) |
© chainreactors, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files in skills/mal-develop of chainreactors/malice-network.
Open the folder on GitHubat commit 6c0e358
Mal Develop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mal Develop this skillchainreactors/malice-network | 500 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Nvim PluginS1M0N38/love2d.nvim | 216 | — | ~1k | Automated safety check: Pass | MIT | |
| Hook Development for Claude Code Pluginsanthropics/claude-plugins-official | 37k | 11 repos | ~4.1k | Automated safety check: Notes | Apache-2.0 | |
| Claude Code Agent Developmentanthropics/claude-plugins-official | 37k | 8 repos | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Claude Code Skill Developer Guidediet103/claude-code-infrastructure-showcase | 10k | 10 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Plugin Settings Patternanthropics/claude-plugins-official | 37k | 7 repos | ~3k | Automated safety check: Pass | Apache-2.0 |
S1M0N38/love2d.nvim
Neovim plugin development best practices and patterns for love2d.nvim.
anthropics/claude-plugins-official
Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.
anthropics/claude-plugins-official
Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.
diet103/claude-code-infrastructure-showcase
A guide to creating and managing Claude Code skills with auto-activation: skill-rules.json triggers, hooks, enforcement levels, YAML frontmatter and progressive disclosure.
anthropics/claude-plugins-official
Shows how Claude Code plugins keep per-project settings and state in .claude/plugin-name.local.md files with YAML frontmatter and a markdown body.
anthropics/claude-plugins-official
Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.
chainreactors/malice-network
IoM Operational Security (OPSEC) advisor. An agent skill from chainreactors/malice-network.
Works with
Categories
MAL (Malice Scripting Language) plugin development guide. An agent skill from chainreactors/malice-network. Mal Develop is an agent skill from chainreactors/malice-network. MAL (Malice Scripting Language) plugin development guide.
Mal Develop fits situations like: conditions: when users want to write MAL plugins; extend IoM commands; write Lua scripts; develop custom modules.
Run `npx skills add chainreactors/malice-network --skill mal-develop -a claude-code`. Or copy the skill folder (skills/mal-develop in chainreactors/malice-network) into .claude/skills/mal-develop in your project. Claude Code loads it when a task matches its description.
Run `npx skills add chainreactors/malice-network --skill mal-develop -a codex`. Or copy the skill folder (skills/mal-develop in chainreactors/malice-network) into .agents/skills/mal-develop in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add chainreactors/malice-network --skill mal-develop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mal-develop, .gemini/skills/mal-develop, .github/skills/mal-develop and .opencode/skills/mal-develop in your project.
SKILL.md names no scripts, command-line tools or credentials: Mal Develop is instructions for the agent only.
SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: chainreactors.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Mal Develop is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Mal Develop: Nvim Plugin (S1M0N38/love2d.nvim, 216 stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 37k stars), Claude Code Agent Development (anthropics/claude-plugins-official, 37k stars) and Claude Code Skill Developer Guide (diet103/claude-code-infrastructure-showcase, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
chainreactors (a GitHub organization) maintains it in chainreactors/malice-network, which has 500 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 5, 2026.
Source: chainreactors/malice-network on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.