smali-dex-patching

Warn

Audited by Socket on Sep 15, 2026

5 alerts found:

Securityx3Anomalyx2
SecurityMEDIUM
SKILL.md

Purpose and capabilities are internally consistent: this is an Android reverse-engineering and APK patching skill, and the files, commands, and tools match that purpose. It is not clearly malicious, but it is a high-risk offensive capability for an AI agent because it teaches bypass of application security controls and can modify/install patched apps; supply-chain risk is present but moderate because referenced tooling is mostly official, same-project, or standard ecosystem sources.

Confidence: 86%Severity: 72%
SecurityMEDIUM
references/detection-evasion.md

The input is a technical guide for bypassing Android application anti-tamper and integrity protections. It does not itself contain executable malware or an exfiltration payload, but it provides concrete instructions for defeating security controls, modifying APK behavior, bypassing SSL pinning, and evading runtime detection. Use should be restricted to authorized testing and analysis.

Confidence: 98%Severity: 86%
SecurityMEDIUM
references/common-patch-patterns.md

The supplied text is a procedural guide for bypassing Android application security controls rather than malware that executes on its own. It contains no direct data theft or malicious runtime behavior, but applying the instructions can disable certificate validation, integrity checks, anti-tampering controls, instrumentation detection, and license enforcement. This creates substantial security and abuse risk in unauthorized use. It should be treated as dual-use offensive guidance, with the highest concern around trust-all SSL patches and forced license bypasses.

Confidence: 99%Severity: 82%
AnomalyLOW
references/dex-format-and-multidex.md

The fragment is security and reverse-engineering documentation. It contains a deliberately unsafe TrustAll TLS-bypass example and guidance for runtime DEX injection, both of which could facilitate application tampering or conceal code when used operationally. However, the supplied text is non-executable documentation and contains no direct data theft, persistence, network exfiltration, or destructive malware behavior.

Confidence: 98%Severity: 56%
AnomalyLOW
references/hooking-vs-patching.md

This fragment is security-testing guidance for bypassing Android integrity checks and SSL pinning. It contains no direct malware payload or data theft mechanism, but it provides actionable instructions for defeating application security controls and producing patched artifacts. Use should be limited to applications owned by or explicitly authorized by the tester.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 15, 2026, 10:01 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fsmali-dex-patching%2F@40c9d7bb4b22ae34debfb716d2899adf5a8af4136565859015ca59e207369934
Security Audit — socket — smali-dex-patching