crypto-technique

Warn

Audited by Socket on Sep 5, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

The skill is internally coherent: its capabilities match its stated purpose, and the explicit install path is low-risk and official. However, the stated purpose is to equip an AI agent with offensive cryptanalysis and exploitation workflows, including secret recovery, signature forgery, and authentication bypass, so the overall skill is high risk despite low malware evidence.

Confidence: 90%Severity: 82%
SecurityMEDIUM
references/prng-oracle-technique.md

No concrete proof of local malware behavior (e.g., credential theft, persistence, or exfiltration) is present in the fragment, but it strongly matches offensive tooling for cryptographic/PRNG compromise: it describes automated remote oracle/protocol interaction and deterministic PRNG state recovery to predict authentication-like tokens. If this content exists as executable dependency code (rather than documentation), it would materially increase an attacker’s capability and warrants high scrutiny. Additional context (the actual package structure and what runs on install/runtime) is required to distinguish documentation from active code.

Confidence: 60%Severity: 70%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fcrypto-technique%2F@2cddd097cfa5f7d641defe88457ba5aad1bf1f048f2b0fbd99061ecb256792ce
Security Audit — socket — crypto-technique