wireless-technique

Fail

Audited by Socket on Sep 5, 2026

5 alerts found:

Securityx3Malwarex2
SecurityMEDIUM
SKILL.md

HIGH risk offensive security skill. Its capabilities are aligned with its stated purpose, but that purpose is to perform wireless credential capture, rogue-AP attacks, and direct access operations with real-world impact. Not confirmed malware, yet clearly unsuitable as a benign helper skill and dangerous to grant an AI agent.

Confidence: 95%Severity: 93%
MalwareHIGH
references/evil-twin.md

This fragment is highly malicious and implements a complete Wi‑Fi credential theft (evil twin) workflow. It uses deauthentication to coerce victim reconnection, rogue AP impersonation, DNS/HTTP(S) redirection to a captive portal, and server-side persistence of user-submitted Wi‑Fi passwords to a local file. It also captures WPA2-Enterprise MSCHAPv2 credential material via hostapd-wpe/eaphammer and includes offline cracking steps. No meaningful benign or defensive software behavior is present in the provided fragment.

Confidence: 96%Severity: 100%
SecurityMEDIUM
references/wpa-attacks.md

No supply-chain malware is evident because the fragment is not a library implementation—it's an offensive command workflow. Still, the actions explicitly enable credential interception/recovery (including active deauthentication/injection, PMKID/handshake/WEP material extraction, and hashcat cracking), which is high-risk and likely illegal/abusive without explicit authorization. Treat as a capability enabling unauthorized access rather than a safe dependency.

Confidence: 84%Severity: 95%
MalwareHIGH
references/sub-ghz-lorawan.md

The fragment is an explicit, highly actionable offensive guide for sub-GHz and LoRaWAN exploitation, including RF capture/replay, ABP key recovery from firmware, node spoofing, forged downlink/command injection, and replay of captured uplinks when frame counters are weak/disabled. It is not obfuscated and contains no software dependency behavior to audit, but its content would materially facilitate unauthorized access, telemetry manipulation, and potentially real-world device control. Treat as high-risk malicious material.

Confidence: 90%Severity: 97%
SecurityMEDIUM
references/iot-zigbee-matter.md

This artifact is not a benign or defensive dependency; it is an offensive, step-by-step attack playbook for Zigbee/Thread/Matter. It includes explicit default cryptographic key material for decrypting join/transport exchanges, prescribes commissioning abuse, and describes replay/injection workflows that can lead to unauthorized control and persistent access. No executable package malware logic exists in the snippet, but the content itself is high-risk misuse material and should be treated as unsafe from a supply-chain/documentation distribution perspective.

Confidence: 82%Severity: 88%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fwireless-technique%2F@2a03130e3f0f47e0cb2b83c7b4f11daf074831552bc76fe9594b6bcdc4cd1333
Security Audit — socket — wireless-technique