frida

Warn

Audited by Socket on Sep 15, 2026

3 alerts found:

Securityx2Anomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install sources are mostly legitimate Frida channels, so this is not confirmed malware, but the skill's actual function is offensive instrumentation: process injection, security-control bypass, anti-detection evasion, and extraction of sensitive runtime data. That footprint is coherent with the stated purpose, yet still high risk for an AI agent because it enables exploit/pentest workflows and can disable TLS/debug protections on real targets.

Confidence: 91%Severity: 78%
SecurityMEDIUM
references/android-ios.md

The fragment contains clearly dual-use but security-invasive Frida examples. Its central behaviors are SSL pinning bypass, runtime control-flow modification, and evasion of Frida and anti-debugging detection. It does not show data theft or persistence, but deploying these scripts against applications without authorization can defeat transport security and application protections. Treat as high security risk for unauthorized use, with malware likelihood lower because no payload delivery, exfiltration, or destructive behavior is present.

Confidence: 98%Severity: 86%
AnomalyLOW
references/hooks-catalog.md

This code is a Frida instrumentation example that compiles native stubs in-memory and uses them to (a) log call-site target addresses when functions are called and (b) optionally patch/replace a target function to change execution flow. While there is no explicit malware behavior such as exfiltration, credential theft, persistence, or command execution in the shown fragment, the included in-process code patching/replacement primitives are security-significant and could be abused for malicious runtime manipulation in a broader context. Treat as medium-to-high risk due to powerful control-flow modification capability despite limited apparent payload logic.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Ffrida%2F@ea429b1cd4ad38001b6764f4d3c31f90eb9a257d12731e4c78767837de437bb5
Security Audit — socket — frida