hardware-technique

Fail

Audited by Socket on Sep 5, 2026

3 alerts found:

Securityx2Malware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for hardware exploitation and firmware extraction, but its purpose is offensive security: it enables credential extraction, bootloader manipulation, brute-force/default-credential attacks, persistence, and secure-boot bypass on real devices. The only flagged install issues are proportionate and mostly documentary, but the overall skill remains high risk because it equips an AI agent with practical offensive techniques against embedded targets.

Confidence: 91%Severity: 76%
SecurityMEDIUM
references/serial-console-attacks.md

This fragment is a highly actionable UART/serial console exploitation playbook. It guides an operator from physical UART access through interactive bootloader control (U-Boot/barebox) to root shell acquisition and sensitive credential dumping, and it further describes multiple secure-boot/verified-boot bypass approaches. While it is not obfuscated or a self-executing malware payload, its content is strongly attacker-enabling and represents a high security risk if distributed as part of a software dependency or repository artifact.

Confidence: 85%Severity: 92%
MalwareHIGH
references/peripheral-protocol-attacks.md

This fragment is not benign source code; it is an offensive exploitation playbook for compromising network printers/peripherals. It explicitly enables sensitive data exfiltration (filesystem reads, NVRAM/config/PIN extraction) and persistence via attacker-uploaded scripts using protocol path traversal. If such content were packaged or distributed as part of a dependency, it would represent an extremely high malicious guidance/supply-chain risk due to its direct, actionable instructions for unauthorized compromise and persistence.

Confidence: 90%Severity: 99%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fhardware-technique%2F@4597cd0c7c80e876b3d0633dc06a1b47739697981a63b0b88e8a659422cc67bf
Security Audit — socket — hardware-technique