evasion_integrate

evasion_integrate is a command for Claude Code from SeaOf0/dsh-redteam-model. It costs 0 tokens per session (517 once invoked), scanned A, a copy of evasion_integrate, MIT.

A command that adds code-obfuscation and anti-analysis techniques to an existing shellcode loader. A shellcode loader is a program that loads and runs shellcode, and these techniques are commonly associated with avoiding detection or analysis.

In plain words
What is it for?
Use it with loader source code when testing or developing evasion techniques, optionally choosing technique types, complexity, or IDs.
Why use it?
It automates selecting techniques, checking whether they fit the loader, applying them, compiling the result, and listing the changes.

Command for Claude Code

Written for Claude Code: argument-hint in frontmatter. Also seen: mentions subagents.

Good fit Use it with loader source code when testing or developing evasion techniques, optionally choosing technique types, complexity, or IDs.

Compare 6 commands from other repositories ↓
Install with agentmods
npx agentmods add commands/seaof0/dsh-redteam-model/evasion_integrate
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/SeaOf0/dsh-redteam-model

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for evasion_integrate

README.md
[![agentmods](https://agentmods.dev/badge/commands/seaof0/dsh-redteam-model/evasion_integrate/github.svg)](https://agentmods.dev/commands/seaof0/dsh-redteam-model/evasion_integrate)
Your own site
<a href="https://agentmods.dev/commands/seaof0/dsh-redteam-model/evasion_integrate"><img src="https://agentmods.dev/badge/commands/seaof0/dsh-redteam-model/evasion_integrate/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for evasion_integrate

Your own site · 80×15
<a href="https://agentmods.dev/commands/seaof0/dsh-redteam-model/evasion_integrate"><img src="https://agentmods.dev/badge/commands/seaof0/dsh-redteam-model/evasion_integrate.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 517 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.00517
Opus 5 $0.00000 $0.00259
Sonnet 5 $0.00000 $0.00103
Haiku 4.5 $0.00000 $0.00052

Measured 9d ago against content hash e4e5f0dae148, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

evasion_integrate scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to evasion_integrate — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

modes/av-evasion/refs/subagents/commands/evasion_integrate.md · 61 lines

What it actually says

Evasion Integrate Command

Launch the evasion-agent to add evasion techniques to an existing loader.

Usage

/evasion_integrate /path/to/loader.c                           # Auto-select techniques
/evasion_integrate /path/to/loader.c --type api_obfuscation    # Specific type
/evasion_integrate /path/to/loader.c --type string_obfuscation,anti_analysis
/evasion_integrate /path/to/loader.c --complexity simple       # Filter by complexity
/evasion_integrate /path/to/loader.c --technique T001,T003     # Specific IDs

What This Command Does

  1. Reads user-provided loader source code
  2. Queries evasion techniques from knowledge base
  3. Analyzes compatibility with the loader
  4. Integrates selected techniques into the code
  5. Compiles modified loader
  6. Reports all changes made

Evasion Types

Type Description Complexity
api_obfuscation API hashing, PEB walking medium
string_obfuscation XOR encryption, stack strings simple
memory_evasion Permission flipping (RW→RX) simple
execution_evasion Direct/indirect syscall complex
anti_analysis Anti-debug, anti-VM medium
amsi_etw_bypass AMSI/ETW patching medium
unhooking NTDLL unhooking complex

Output

  • Modified source: output/evasion_<id>.c
  • Compiled executable: output/evasion_<id>.exe
  • Changes summary:
    • Techniques applied
    • APIs modified
    • Detection risk assessment

Security

  • ONLY modify user-provided code
  • NEVER run generated executables
  • Compilation success is sufficient

Agent

Spawns evasion-agent subagent for technique integration.

See evasion_integrate skill for detailed patterns.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 61 lines · 0 tokens per session scan A e4e5f0dae148

Subscribe to this mod's changes

evasion_integrate is a command published in the GitHub repository SeaOf0/dsh-redteam-model (325 stars, last pushed 4d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 517 tokens. A static security scan graded it A with 0 findings. It is 100% identical to evasion_integrate, differing in 0 lines, and is treated as a copy.