analyzing-malicious-onenote-and-html-smuggling

analyzing-malicious-onenote-and-html-smuggling is a skill for Claude Code, Codex from meltedinhex/analyst-ai-pack. It costs 78 tokens per session (807 once invoked), scanned A, original, Apache-2.0.

A static-analysis guide for malicious OneNote attachments and HTML smuggling. OneNote files can hide payloads behind fake buttons, while HTML smuggling rebuilds a file in the browser from embedded data.

In plain words
What is it for?
Use it to carve executables and scripts from OneNote files, detect embedded browser data, recover reconstructed payloads, and identify related URLs or code.
Why use it?
It helps recover hidden files without opening the OneNote document or webpage through the delivery mechanism.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to carve executables and scripts from OneNote files, detect embedded browser data, recover reconstructed payloads, and identify related URLs or code.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/meltedinhex/analyst-ai-pack/analyzing-malicious-onenote-and-html-smuggling
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add meltedinhex/analyst-ai-pack --skill analyzing-malicious-onenote-and-html-smuggling
Clone the repo
git clone --depth 1 https://github.com/meltedinhex/analyst-ai-pack

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for analyzing-malicious-onenote-and-html-smuggling

README.md
[![agentmods](https://agentmods.dev/badge/skills/meltedinhex/analyst-ai-pack/analyzing-malicious-onenote-and-html-smuggling/github.svg)](https://agentmods.dev/skills/meltedinhex/analyst-ai-pack/analyzing-malicious-onenote-and-html-smuggling)
Your own site
<a href="https://agentmods.dev/skills/meltedinhex/analyst-ai-pack/analyzing-malicious-onenote-and-html-smuggling"><img src="https://agentmods.dev/badge/skills/meltedinhex/analyst-ai-pack/analyzing-malicious-onenote-and-html-smuggling/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for analyzing-malicious-onenote-and-html-smuggling

Your own site · 80×15
<a href="https://agentmods.dev/skills/meltedinhex/analyst-ai-pack/analyzing-malicious-onenote-and-html-smuggling"><img src="https://agentmods.dev/badge/skills/meltedinhex/analyst-ai-pack/analyzing-malicious-onenote-and-html-smuggling.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 78 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 807 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00078 $0.00807
Opus 5 $0.00039 $0.00404
Sonnet 5 $0.00016 $0.00161
Haiku 4.5 $0.00008 $0.00081

Measured 11d ago against content hash 4a2005c4bfa0, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

analyzing-malicious-onenote-and-html-smuggling scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (scripts/analyst.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/analyzing-malicious-onenote-and-html-smuggling/SKILL.md · 94 lines

How it starts

The opening of the file, as written. The whole thing — 94 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Analyzing Malicious OneNote and HTML Smuggling

When to Use

  • You have a OneNote (.one) attachment suspected of hiding an embedded executable/script behind a "click to view" lure.
  • You have an HTML/SVG page that reconstructs and auto-downloads a payload from an embedded blob (HTML smuggling).
  • You need to extract the hidden payload without triggering the lure.

Do not use OneNote or a browser to open these files for analysis — that is exactly the delivery mechanism. Carve the embedded data statically.

Prerequisites

  • A static carver (Python) for embedded file signatures; the sample handled inertly.

Safety & Handling

  • Never open the .one in OneNote or the HTML in a browser.
  • Defang URLs and store carved payloads password-protected.

Workflow

Step 1: For OneNote — carve embedded files

OneNote stores attached files in the document. Scan for embedded file signatures (MZ, script headers, archives) and the FileDataStoreObject GUIDs, and carve them out.

python scripts/analyst.py carve sample.one

Step 2: For HTML smuggling — find the embedded blob

Look for large base64/Blob/Uint8Array constructions, data: URIs, and a JS routine that builds a Blob and triggers a download (msSaveOrOpenBlob, anchor download, createObjectURL).

Step 3: Reconstruct the payload statically

Decode the embedded base64/byte array (and any XOR/char-code layer) to recover the payload as data — without executing the page.

Step 4: Analyze and extract IOCs

Hash carved payloads, identify their type, defang any URLs, and route executables/scripts to the appropriate analysis workflow.

Validation

  • Embedded payloads are carved/reconstructed from the inert file, not by opening it.
  • The recovered payload's type is identified and hashed.
  • The lure/trigger mechanism (fake button, Blob download) is documented.

Pitfalls

  • Opening the OneNote/HTML to "see" the lure and executing the payload.
  • Decoding only the first layer when the blob is additionally XOR/char-code encoded.
  • Missing multiple embedded objects in a single OneNote page.

Read the full file on GitHub · 94 lines

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 94 lines · 78 tokens per session scan A 4a2005c4bfa0

Subscribe to this mod's changes

analyzing-malicious-onenote-and-html-smuggling is a skill published in the GitHub repository meltedinhex/analyst-ai-pack (22 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 78 tokens to every session and 807 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

analyzing-golang-malware-with-ghidra

Reverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo and pclntab structures, recovering stripped/obfuscated function names (e.g. via GoResolver), and extracting embedded module/dependency strings and types from Go binaries. Use when analyzing a Go-language malware sample, deobfuscating a…

mukul975/Anthropic-Cybersecurity-Skills · 95 tokens

analyzing-malicious-pdf-with-peepdf

Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects. Use when triaging a suspicious PDF attachment from a phishing email, analyzing a PDF-based exploit document, or building detection signatures for weaponized PDF…

mukul975/Anthropic-Cybersecurity-Skills · 73 tokens

analyzing-malicious-pdf-with-peepdf

A Chinese-language skill for examining suspicious PDF files with peepdf, pdfid, and pdf-parser. It is intended for static malware analysis, which studies a file without running it.

killvxk/cybersecurity-skills-zh · 50 tokens

analyzing-malicious-pdf-with-peepdf

Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.

26zl/cybersec-toolkit · 43 tokens

analyzing-malicious-pdf-with-peepdf

Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.

plurigrid/asi · 43 tokens

analyzing-malicious-pdf-with-peepdf

Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.

pinkpixel-dev/skills-collection-1 · 43 tokens