jtag-swd

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and does not show malware traits, credential theft, or suspicious third-party data routing, but its purpose is explicitly firmware extraction and protection bypass on hardware targets. Treat as a high-impact offensive-capable hardware security skill rather than benign general developer guidance.

Confidence: 89%Severity: 72%
MalwareHIGH
references/stm32-rdp-bypass.md

This fragment is not software malware, but it is a highly actionable exploit-oriented instruction set for defeating STM32 hardware readout protection (including a destructive OpenOCD unlock and detailed physical glitching guidance to bypass without mass erase). From a supply-chain security standpoint, publishing or distributing this artifact materially increases capability for unauthorized debug access and firmware extraction, representing a high security risk despite the absence of executable code behavior.

Confidence: 82%Severity: 90%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fjtag-swd%2F@3d6c4e3c952654d6f5e330e8bb3fc0ed56c5020219c8be0054138cf994b492d0
Security Audit — socket — jtag-swd